9.1.8 Ensure enabling of external data sharing is restricted

Information

Power BI admins can specify which users or user groups can share datasets externally with guests from a different tenant through the in-place mechanism. Disabling this setting prevents any user from sharing datasets externally by restricting the ability of users to turn on external sharing for datasets they own or manage.

The recommended state is Enabled for a subset of the organization or Disabled.

Establishing and enforcing a dedicated security group prevents unauthorized access to Microsoft Fabric for guests collaborating in Azure that are new or from other applications. This upholds the principle of least privilege and uses role-based access control (RBAC). These security groups can also be used for tasks like conditional access, enhancing risk management and user accountability across the organization.

Solution

To remediate using the UI:

- Navigate to Microsoft Fabric https://app.powerbi.com/admin-portal
- Select Tenant settings.
- Scroll to Export and Sharing settings.
- Set Allow specific users to turn on external data sharing to one of these states:

- Disabled
- Enabled with Specific security groups selected and defined.

Important: If the organization doesn't actively use this feature it is recommended to keep it Disabled.

Impact:

Security groups will need to be more closely tended to and monitored.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4), 800-53|MP-2

Plugin: microsoft_azure

Control ID: f5ee99b43a7fe176192da2bb38df316db1c30459d078214df3312595f2c02199