Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Hidden columns can be revealed by users who should not have rights

Hi Community,

I recently discovered a minor security bug.

We have created our data model by using Power Pivot. Based on this same data model we create two Excel files. One of these containing all business critical information, lets call this "Cube Critical" and the other where these critical columns and calculated measures are hidden. Let's call this "Cube Normal."

We then upload these two files to the Power BI Service and create two different content packs which we share to the people based on their roles/responsibilities. The hidden columns are truly hidden when creating reports on Power BI Service.

However, when people with access to "Cube Normal" connects to this data set using Power BI Desktop ->  Get Data -> Online Services -> Power BI Service they can reveal  the hidden columns by right clicking the filter pane and selecting "View Hidden"

I think this is a security bug?

Status: New
Comments
v-haibl-msft
Employee

@slahtinen

 

According to this article, the ability to hide columns is not intended to be used for data security, only to simplify and shorten the list of columns visible to reports that use them.

I think you should implement row level security.

 

Best Regards,
Herbert