Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
willharris24
Advocate I
Advocate I

Security issues - sharing reports with external users - potential breach concern

Hi - 

 

A client has shared some power bi reports with external users.

As a result, these users are now registed as guest users on the client's AD tenant.

 

During the sign in process, once the external user has authenticated, they come to the https://account.activedirectory.windowsazure.com page for the client's AD tenant...  this shows that they have no apps - but it does show the "Groups" logo.

 

External guest users can click this and are able to see all of the groups in the organisation - but more critically when you click on a group you can see all of the group users and their IDs (email addresses).    

 

Anyone know which settings need to be shut down to prevent this?  Obviously we don't want external guests to be able to see email addresses of other users.   

 

 

 

 

 

 

1 REPLY 1
v-frfei-msft
Community Support
Community Support

Hi @willharris24 ,

 

Based on my research, I cannot find a way to hide the email address in AAD. I recommend to recreate a post in AAD Consumer Forum.

 

Community Support Team _ Frank
If this post helps, then please consider Accept it as the solution to help the others find it more quickly.

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors