9.1.9 (L1) Ensure 'Block ResourceKey Authentication' is 'Enabled'

Information

This setting blocks the use of resource key based authentication. The Block ResourceKey Authentication setting applies to streaming and PUSH datasets. If blocked users will not be allowed to send data to streaming and PUSH datasets using the API with a resource key.

The recommended state is Enabled

Resource keys are a form of authentication that allows users to access Power BI resources (such as reports, dashboards, and datasets) without requiring individual user accounts. While convenient, this method bypasses the organization's centralized identity and access management controls. Enabling ensures that access to Power BI resources is tied to the organization's authentication mechanisms, providing a more secure and controlled environment.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

- Navigate to Microsoft Fabric

https://app.powerbi.com/admin-portal

- Select Tenant settings
- Scroll to Developer settings
- Set Block ResourceKey Authentication to Enabled

Impact:

Developers will need to request a special exception in order to use this feature.

See Also

https://workbench.cisecurity.org/benchmarks/20006

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: microsoft_azure

Control ID: c3f60b29e4bb78b0c24e381793fb36e3ea301cc2bc6b024e341a57e757d345e6