Skip to main content

Power BI

New

Contributor able to send preview images when subscribing for others is a security risk.

Vote (1) Share
Arunava Sarkar's profile image

Arunava Sarkar on 24 May 2023 14:58:32

Users in the workspace `contributor` role do not have permission to share or manage permissions. Yet, I am observing that the contributor can subscribe others to a report and send the preview image of the report in the subscription email.  I know that ability to subscribe others is not a security risk because unless the end user has permission, they cannot open the link in the subscription email. However, allowing contributor to send the preview image is a security risk.