9.1.4 (L1) Ensure 'Publish to web' is restricted

Information

Power BI enables users to share reports and materials directly on the internet from both the application's desktop version and its web user interface. This functionality generates a publicly reachable web link that doesn't necessitate authentication or the need to be an Entra ID user in order to access and view it.

The recommended state is Enabled for a subset of the organization or Disabled

When using Publish to Web anyone on the Internet can view a published report or visual. Viewing requires no authentication. It includes viewing detail-level data that your reports aggregate. By disabling the feature, restricting access to certain users and allowing existing embed codes organizations can mitigate the exposure of confidential or proprietary information.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Fabric

https://app.powerbi.com/admin-portal

- Select Tenant settings
- Scroll to Export and Sharing settings
- Set Publish to web to one of these states:
- State 1: Disabled
- State 2: Enabled with Choose how embed codes work set to Only allow existing codes AND Specific security groups selected and defined

Important: If the organization doesn't actively use this feature it is recommended to keep it Disabled

Impact:

Depending on the organization's utilization administrators may experience more overhead managing embed codes, and requests.

See Also

https://workbench.cisecurity.org/benchmarks/17682

Item Details

Category: PLANNING, SYSTEM AND SERVICES ACQUISITION

References: 800-53|PL-8, 800-53|SA-8

Plugin: microsoft_azure

Control ID: c19d143ddce41cb880b9d8cbc46353035011e9e3328ea2d835a09f8d4aaad41f