Let’s talk about the most dangerous setting of the nearly 170 settings in the portal: Publish to Web. Enabling this setting allows users in your organization to publish internal reports to the open internet without authentication. There is the occasional reason to have this enabled (government transparency dashboards, other non-profit reporting, etc.) and if that is the case, at the very minimum, only members of a security group should be granted the ability. If you are surprised to see this setting turned on, you can view the public reports that have been published in the Embed Codes section in the admin portal.
Recommendation: Disable for all users. If needed and a valid use case, only allow for specialized security groups.
The second setting, "Allow shareable links to grant access to everyone in your org,” causes oversharing and can expose reports to users in departments that shouldn’t have access. With this setting enabled, users can share a link that can travel around the entire organization with little control and a challenging audit trail.
Recommendation: Disable this feature or restrict to select security groups/center of excellence.
Finding this setting is a bit awkward. In the Admin Portal, you navigate to Capacity Settings (1), Fabric Capacity (2), and then click on the name of the capacity you’re trying to edit (3). This opens settings for that specific capacity.
Once there, head to notifications. The default on Fabric Capacities is that admins do not receive notifications when the capacity is exceeded or reaches the 100% threshold. Reports will start throttling, and users will experience slower performance.
Recommendation: Enable notifications. At the very minimum check when you’ve exceeded available capacity, and send the notifications to the admins, or preferably a security group of admins. Displaying a banner message to users is also recommended so they know why they’re experiencing throttling. To be more proactive, set the first setting below 100 (80 - 90). Each organization has different sensitivity to hitting the capacity limit, so there isn’t a firm number to recommend here.
These three settings can be checked in an afternoon. They are just three of nearly 170 tenant settings, and tenant settings are only one layer. Workspace roles, sensitivity labels, guest access, passwords stored in fabric notebooks, and external sharing all sit beneath them. If you’re interested in a Fabric & Power BI Security Assessment for a thorough scan of your tenant, reach out to our team of data security experts.