cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
Highlighted
Tamir Helper V
Helper V

Custom Visualization Data Security Issues

Hello,

 

In the description of every Custom visualization that is on the https://appsource.microsoft.com, it says that the visualization can send data through the Internet.

 

What data is being sent? Isn't it a severe breach of data confidentiality? 

If I make reports and dashboards inside my Organization, doesn't it leaks?

 

I would appreciate your answers,

 

Thanks,

Tamir

2 ACCEPTED SOLUTIONS

Accepted Solutions
v-viig Community Champion
Community Champion

Re: Custom Visualization Data Security Issues

Certified custom visuals and custom visuals developed by Microsoft don’t send any data over internet. Such custom visuals can be used for sensitive data.

However, we can’t be sure about other third party not-certified custom visuals.

 

Ignat Vilesov,

Software Engineer

 

Microsoft Power BI Custom Visuals

pbicvsupport@microsoft.com

View solution in original post

v-viig Community Champion
Community Champion

Re: Custom Visualization Data Security Issues

Some custom Visuals might send data to third-party services for additional analytics.

We'd recommned to contact developers of custom visuals to ask what data their CVs send.

 

We'd also recommend to use certified CV. Tag certified means that we have not find any security issues and sending data to 3rd party services.

 

Ignat Vilesov,

Software Engineer

 

Microsoft Power BI Custom Visuals

pbicvsupport@microsoft.com

View solution in original post

12 REPLIES 12
Community Support
Community Support

Re: Custom Visualization Data Security Issues

Hi @Tamir,

 

>>What data is being sent? Isn't it a severe breach of data confidentiality? 

For power bi data security, you can refer to following article:

POWER BI AND DATA SECURITY – COMPLIANCE AND ENCRYPTION

 

>>In the description of every Custom visualization that is on the https://appsource.microsoft.com, it says that the visualization can send data through the Internet.

Do you means the origination content pack? If this is a case, all receivers has the similar data access permission as owner.

You can also take a look at below link to know more about content pack:

Intro to organizational content packs in Power BI

 

Data security

All distribution group members have the same permissions to the data as the content pack creator. The one exception to this is SQL Server Analysis Services (SSAS) on-premises tabular datasets. Because the reports and dashboards are connecting live to the on-premises SSAS model, the credentials of each individual distribution group member are used to determine the data he or she can access.

 

BTW, you can add dynamic rls on your report to improve data security level:

RLS with UserName()

 

 

Regards,
Xiaoxin Sheng

Community Support Team _ Xiaoxin
If this post helps, please consider Accept it as the solution to help the other members find it more quickly.
Tamir Helper V
Helper V

Re: Custom Visualization Data Security Issues

Hi @v-shex-msft

 

Thank you for your detailed answer. I will go thoroughly over it.

However, I was referring to something a little bit different.

Please see a snapshot: (blue circle)

 

Thank you,

Tamir

Capture.JPG

Community Support
Community Support

Re: Custom Visualization Data Security Issues

Hi @Tamir,

 

I'm also not clarity for this, maybe you can try to contact to power bi custom visual team for further support.

 

Regards,

Xiaoxin Sheng

Community Support Team _ Xiaoxin
If this post helps, please consider Accept it as the solution to help the other members find it more quickly.
Tamir Helper V
Helper V

Re: Custom Visualization Data Security Issues

Thank you.

Regards,

Tamir

v-viig Community Champion
Community Champion

Re: Custom Visualization Data Security Issues

Certified custom visuals and custom visuals developed by Microsoft don’t send any data over internet. Such custom visuals can be used for sensitive data.

However, we can’t be sure about other third party not-certified custom visuals.

 

Ignat Vilesov,

Software Engineer

 

Microsoft Power BI Custom Visuals

pbicvsupport@microsoft.com

View solution in original post

ForcaTaico Resolver II
Resolver II

Re: Custom Visualization Data Security Issues

Hi, 

 

Is there a way to only enable certified/MS custom visuals in PBIRS? We need to make sure that the custom visuals does not send data over the Internet.

 

Also the list doesnt seem to get updated. For ex. Timeline Storyteller isnt on (which is published by Microsoft)

https://docs.microsoft.com/en-us/power-bi/power-bi-custom-visuals-certified

 

Regards Taico

v-viig Community Champion
Community Champion

Re: Custom Visualization Data Security Issues

There's no way at least for now. The organisation store for custom visuals is coming soon to cover this functionality.

 

Ignat Vilesov,

Software Engineer

 

Microsoft Power BI Custom Visuals

pbicvsupport@microsoft.com

ForcaTaico Resolver II
Resolver II

Re: Custom Visualization Data Security Issues

Hi,

 

Thanks for the reply.

 

'Organisation store for custom visuals' sounds great and would solve the issue.

 

-Taico

eitanl Helper II
Helper II

Re: Custom Visualization Data Security Issues

Hi is there a why to avoid this exposure?

why is microsoft allowing the third party to: "read and make changes to your documents" and "Send data over the internet".

 

 

is there a why to find the information that was sent/changed by the add-in

 

 

 

 

Helpful resources

Announcements
Announcing the New Spanish Forum

Announcing the New Spanish Forum

Do you need help in Spanish? Check out our new Spanish community section.

MBAS Gallery 2020

MBAS Gallery 2020

Watch Microsoft Business Applications Summit sessions on-demand.

‘Better Together’ Integration Forum Launch

‘Better Together’ Integration Forum Launch

We've launched a how-to forum where you can learn about how Power BI integrates with other Power Platform products.

Top Solution Authors
Top Kudoed Authors