Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
rajeevshah
New Member

CRITICAL ISSUE (data breach) on PowerBI service for paginated reports connected to AAS cubes

Hello friends,

 

We are using AAS cubes. We also have setup Azure B2B users and have shared the PowerBI portal (BI reports) to the extended organization. We have Role based authentication (RBA) setup, so that each of the extended org can see only their data.

since the past week, this has stopped working on paginated reports on the service. It does not respect RBA.

If one downloads the PBRS report and connects using the Azure B2B id, it respects, but the moment it is published to the portal, it ignores RBA.

 

This causes a data breach as anyone can see everyone's data. We have had to remove all the paginated reports published on the portal to mitigate the issue.

Just wondering if anyone else has faced this ?

1 REPLY 1
GilbertQ
Super User
Super User

Hi @rajeevshah 

 

Could I ask why you are not using Row Level Security? This will ensure 100% that the data that they see is 100% secure. If they are not in a role they do not se anything.





Did I answer your question? Mark my post as a solution!

Proud to be a Super User!







Power BI Blog

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors