Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
Cado_one
Resolver III
Resolver III

Security risks related to publish to web (public mode)

Hi all,

 

I post this topic because I consider using Power BI embedded reports in an intranet website with the Pulbish to web (public) because not everyone in my company has a pro license.

The website access requires a login and password for the users and the reports would be accessible only if the user is connected to the VPN of the company.

Of course I saw many warning messages saying that reports published that way will be accessible by anyone on the internet.

 

My question : is it possible for an external person to access the reports without having the link only reachable in the source code of the website ? And if the answer is yes, could you tell me how ?

 

Thanks in advance.

Regards,

Cado

1 ACCEPTED SOLUTION
collinq
Super User
Super User

Hi @Cado_one ,

 

They key is the word "intranet".  When you embed to the WWW like this (Power BI Embedded Example : :: Welcome To EPM Strategy ::) then anybody in the world that can get to the internet can see it.  When you embed to the INTRAnet, then anybody that can get to that page can see it.  So, you are protected from the entire world, but, there may be people that can get to that page that you don't expect.  A real life example I encounted was a company that embedded to a specific subsection of their intranet - the Accounting "home page" area.  Anybody in Accounting department could see anything in that part of their internal website so anything embedded there was visible to accounting.  But, no other departments could see it since you have to have permissions to get to that section of intranet.

 

I would appreciate Kudos if my response was helpful. I would also appreciate it if you would Mark this As a Solution if it solved the problem. Thanks!




Did I answer your question? Mark my post as a solution!

Proud to be a Datanaut!
Private message me for consulting or training needs.




View solution in original post

2 REPLIES 2
collinq
Super User
Super User

Hi @Cado_one ,

 

They key is the word "intranet".  When you embed to the WWW like this (Power BI Embedded Example : :: Welcome To EPM Strategy ::) then anybody in the world that can get to the internet can see it.  When you embed to the INTRAnet, then anybody that can get to that page can see it.  So, you are protected from the entire world, but, there may be people that can get to that page that you don't expect.  A real life example I encounted was a company that embedded to a specific subsection of their intranet - the Accounting "home page" area.  Anybody in Accounting department could see anything in that part of their internal website so anything embedded there was visible to accounting.  But, no other departments could see it since you have to have permissions to get to that section of intranet.

 

I would appreciate Kudos if my response was helpful. I would also appreciate it if you would Mark this As a Solution if it solved the problem. Thanks!




Did I answer your question? Mark my post as a solution!

Proud to be a Datanaut!
Private message me for consulting or training needs.




Hi @collinq 

 

Thank you for the answer and testimony it reassures me.

The website is accessible only by O&M department and restrictions will be added to get each reports only visible by the concerned persons.

To go further in security, we could change all embed codes every 3 months.

 

Have a nice day,

Cado

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors