9.1.10 (L1) Ensure access to APIs by service principals is restricted

Information

Use a service principal to access Fabric public APIs that include create, read, update, and delete (CRUD) operations, and are protected by a Fabric permission model.

To allow an app to use service principal authentication, its service principal must be included in an allowed security group. You can control who can access service principals by creating dedicated security groups and using these groups in other tenant settings.

The recommended state is Enabled for a subset of the organization or Disabled.

Leaving API access unrestricted increases the attack surface in the event an adversary gains access to a Service Principal. APIs are a feature-rich method for programmatic access to many areas of Power Bi and should be guarded closely.

Solution

To remediate using the UI:

- Navigate to Microsoft Fabric https://app.powerbi.com/admin-portal
- Select Tenant settings.
- Scroll to Developer settings.
- Set Service principals can call Fabric public APIs to one of these states:
- State 1: Disabled
- State 2: Enabled with Specific security groups selected and defined.

Important: If the organization doesn't actively use this feature it is recommended to keep it Disabled.

Impact:

Service principals will need to be members of specific security groups in order to perform public API calls.

See Also

https://workbench.cisecurity.org/benchmarks/24619

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: microsoft_azure

Control ID: a2df5e9390a25287851c1a557677717fb4ca57034d37e9bc09b38cd825fb989c