Join us for an expert-led overview of the tools and concepts you'll need to pass exam PL-300. The first session starts on June 11th. See you there!
Get registeredFabric Ideas just got better! New features, better search, and direct team engagement. Learn more
Even though we have a security group controlled and locked down to allow for PowerBI Graph API, one of the gaps we see is that we don't get SPN data flowing from PowerBI into Microsoft Defender for Cloud Apps. This means that you can add an SPN to allow for PowerBI graph api and then you can add that SPN to any workspace access and allow for graph API ingestion without any oversight or logging.
We were told it's an architecture design, but this means we can't get alerted when one of these SPNs all of a sudden get added to a sensitive workspace.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.