9.1.11 Ensure service principals cannot create and use profiles

Information

Service principal profiles provide a flexible solution for apps used in a multitenancy deployment. The profiles enable customer data isolation and tighter security boundaries between customers that are utilizing the app.

The recommended state is Enabled for a subset of the organization or Disabled.

Service Principals should be restricted to a security group to limit which Service Principals can interact with profiles. This supports the principle of least privilege.

Solution

To remediate using the UI:

- Navigate to Microsoft Fabric https://app.powerbi.com/admin-portal
- Select Tenant settings.
- Scroll to Developer settings.
- Set Allow service principals to create and use profiles to one of the following:

- Disabled
- Enabled with Specific security groups selected and defined.

Important: If the organization doesn't actively use this feature it is recommended to keep it Disabled.

Impact:

Disabled is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4), 800-53|CM-6, 800-53|CM-7

Plugin: microsoft_azure

Control ID: c8b10a06affdc0fd69d8ce41f4fa52ee1f96fcf8d4d685cbd1f7f1e3b8e5ff5e