Подія
31 бер., 23 - 2 квіт., 23
Найбільша подія навчання Fabric, Power BI і SQL. 31 березня – 2 квітня. Щоб заощадити 400 грн, скористайтеся кодом FABINSIDER.
Реєструйтеся сьогодніЦей браузер більше не підтримується.
Замініть його на Microsoft Edge, щоб користуватися перевагами найновіших функцій, оновлень безпеки та технічної підтримки.
By using Defender for Cloud Apps with Power BI, you can help protect your Power BI reports, data, and services from unintended leaks or breaches. With Defender for Cloud Apps, you can create conditional access policies for your organization's data, by using real-time session controls in Microsoft Entra ID, that help to ensure your Power BI analytics are secure. Once these policies are set, administrators can monitor user access and activity, perform real-time risk analysis, and set label-specific controls.
Примітка
Microsoft Defender for Cloud Apps is now part of Microsoft Defender XDR. For more information, see Microsoft Defender for Cloud Apps in Microsoft Defender XDR.
You can configure Defender for Cloud Apps for all sorts of apps and services, not only Power BI. You'll need to configure Defender for Cloud Apps to work with Power BI to benefit from Defender for Cloud Apps protections for your Power BI data and analytics. For more information about Defender for Cloud Apps, including an overview of how it works, the dashboard, and app risk scores, see the Defender for Cloud Apps documentation.
To use Defender for Cloud Apps with Power BI, you must use and configure relevant Microsoft security services, some of which are set outside Power BI. In order to have Defender for Cloud Apps in your tenant, you must have one of the following licenses:
Примітка
A Microsoft Entra ID P1 license is required in order to benefit from Defender for Cloud Apps real-time controls.
The following sections describe the steps for configuring real-time controls for Power BI with Defender for Cloud Apps.
The steps necessary to set session controls are completed in the Microsoft Entra ID and Defender for Cloud Apps portals. In the Microsoft Entra admin center, you create a conditional access policy for Power BI, and route sessions used in Power BI through the Defender for Cloud Apps service.
Defender for Cloud Apps operates in a reverse-proxy architecture, and is integrated with Microsoft Entra Conditional Access to monitor Power BI user activity in real-time. The following steps are provided to help you understand the process, and detailed step-by-step instructions are provided in the linked content in each of the following steps. For a description of the whole process, see Defender for Cloud Apps.
The process for setting session policies is described in detail in Session policies.
You can define anomaly Power BI detection policies that can be independently scoped, so that they apply to only the users and groups you want to include and exclude in the policy. For more information, see Anomaly detection policies.
Defender for Cloud Apps has two dedicated, built-in detections for Power BI. See Built-in Defender for Cloud Apps detections for Power BI.
Sensitivity labels enable you to classify and help protect sensitive content, so that people in your organization can collaborate with partners outside your organization, yet still be careful and aware of sensitive content and data.
For information about the process of using sensitivity labels for Power BI, see Sensitivity labels in Power BI. See the example later in this article of a Power BI policy based on sensitivity labels.
Defender for Cloud Apps activity policies enable administrators to define their own custom rules to help detect user behavior that deviates from the norm, and even possibly act upon it automatically, if it seems too dangerous. For example:
Massive sensitivity label removal. For example, alert me when sensitivity labels are removed by a single user from 20 different reports in a time window shorter than 5 minutes.
Encrypting sensitivity label downgrade. For example, alert me when a report that had a Highly confidential sensitivity label is now classified as Public.
Примітка
The unique identifiers (IDs) of Power BI artifacts and sensitivity labels can be found using Power BI REST APIs. See Get semantic models or Get reports.
Custom activity policies are configured in the Defender for Cloud Apps portal. For more information, see Activity policies.
Defender for Cloud Apps detections enable administrators to monitor specific activities of a monitored app. For Power BI, there are currently two dedicated, built-in Defender for Cloud Apps detections:
Suspicious share – detects when a user shares a sensitive report with an unfamiliar (external to the organization) email. A sensitive report is a report whose sensitivity label is set to INTERNAL-ONLY or higher.
Mass share of reports – detects when a user shares a massive number of reports in a single session.
Settings for these detections are configured in the Defender for Cloud Apps portal. For more information, see Unusual activities (by user).
A new role is created for Power BI admins when using Defender for Cloud Apps with Power BI. When you sign in as a Power BI admin to the Defender for Cloud Apps portal, you have limited access to data, alerts, users at risk, activity logs, and other information relevant to Power BI.
Using Defender for Cloud Apps with Power BI is designed to help secure your organization's content and data, with detections that monitor user sessions and their activities. When you use Defender for Cloud Apps with Power BI, there are a few considerations and limitations you should keep in mind:
Застереження
In the session policy, in the "Action" part, the "protect" capability works only if no label exists on the item. If a label already exists, the "protect" action won't apply; you can't override an existing label that has already been applied to an item in Power BI.
The following example shows you how to create a new session policy using Defender for Cloud Apps with Power BI.
First, create a new session policy. In the Defender for Cloud Apps portal, select Policies on the navigation pane. Then on the policies page, select Create policy and choose Session policy.
In the window that appears, create the session policy. The numbered steps describe settings for the following image.
In the Policy template dropdown, choose No template.
For Policy name, provide a relevant name for your session policy.
For Session control type, select Control file download (with inspection) (for DLP).
For the Activity source section, choose relevant blocking policies. We recommend blocking un-managed and non-compliant devices. Choose to block downloads when the session is in Power BI.
More options appear when you scroll down. The following image shows those options, with other examples.
Create a filter on Sensitivity label and choose Highly confidential or whatever best fits your organization.
Change the Inspection method to none.
Choose the Block option that fits your needs.
Create an alert for such an action.
Select Create to complete the session policy.
This article described how Defender for Cloud Apps can provide data and content protections for Power BI. For more information about Data Protection for Power BI and supporting content for the Azure services that enable it, see:
For information about Azure and security articles, see:
Подія
31 бер., 23 - 2 квіт., 23
Найбільша подія навчання Fabric, Power BI і SQL. 31 березня – 2 квітня. Щоб заощадити 400 грн, скористайтеся кодом FABINSIDER.
Реєструйтеся сьогодніНавчання
Модуль
Configure DLP policies for Microsoft Defender for Cloud Apps and Power Platform - Training
Configure DLP policies for Microsoft Defender for Cloud Apps and Power Platform
Сертифікація
Microsoft Certified: Information Protection and Compliance Administrator Associate - Certifications
Демонстрація основ безпеки даних, керування життєвим циклом, інформаційної безпеки та відповідності вимогам для захисту розгортання Microsoft 365.
Документація
Power BI implementation planning: Defender for Cloud Apps for Power BI - Power BI
Learn about using Defender for Cloud Apps with Power BI.