Information
This setting allows business-to-business (B2B) guests access to Microsoft Fabric, and contents that they have permissions to. With the setting turned off, B2B guest users receive an error when trying to access Power BI.
The recommended state is Enabled for a subset of the organization or Disabled
Establishing and enforcing a dedicated security group prevents unauthorized access to Microsoft Fabric for guests collaborating in Azure that are new or assigned guest status from other applications. This upholds the principle of least privilege and uses role-based access control (RBAC). These security groups can also be used for tasks like conditional access, enhancing risk management and user accountability across the organization.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
To remediate using the UI:
- Navigate to Microsoft Fabric
https://app.powerbi.com/admin-portal
- Select Tenant settings
- Scroll to Export and Sharing settings
- Set Guest users can access Microsoft Fabric to one of these states:
- State 1: Disabled
- State 2: Enabled with Specific security groups selected and defined.
Important: If the organization doesn't actively use this feature it is recommended to keep it Disabled
Impact:
Security groups will need to be more closely tended to and monitored.