Power BI
NewContributor able to send preview images when subscribing for others is a security risk.
Vote
(1)
Arunava Sarkar on 24 May 2023 14:58:32
Users in the workspace `contributor` role do not have permission to share or manage permissions. Yet, I am observing that the contributor can subscribe others to a report and send the preview image of the report in the subscription email. I know that ability to subscribe others is not a security risk because unless the end user has permission, they cannot open the link in the subscription email. However, allowing contributor to send the preview image is a security risk.