Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why does report sharing in Microsoft Fabric create…
Cyber Security

Why does report sharing in Microsoft Fabric create a data exposure risk even when the visible report looks restricted?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

Report sharing can expose the underlying semantic model, which Q&A can query beyond what the report visibly shows. That means a user may ask for excluded fields and still retrieve sensitive values if the model remains accessible. The risk is amplified when links are broadly shared, because the effective audience can become much larger than the report creator intended.

How the exposure happens even when the report view is narrow

The key distinction is between what the report renders and what the shared asset still permits. In Microsoft Fabric, the visible report can be tightly filtered or limited, yet sharing may still grant access to the underlying semantic model. If that model remains queryable, the report becomes only one presentation layer, not the full security boundary.

That matters because the effective permission boundary is defined by the model and its connected data, not just by the fields shown in the report canvas. Users who can interact with the model may be able to discover values that were intentionally left off the report page, especially when the model exposes relationships, measures, or columns that were never meant for casual viewing.

Why Q&A turns a presentation issue into a data exposure issue

Q&A changes the risk profile because it is not limited to the exact visuals the author chose. A recipient can ask for data that the report UI does not surface, and the semantic model may answer if it has access to the relevant tables or columns. In practice, this means a “restricted-looking” report can still behave like a broader data access path.

That creates a mismatch between user expectation and system behaviour. Report authors often think in terms of screen layout, but the security question is whether the shared object also exposes the underlying analytical source. If the model is shared more broadly than intended, Q&A can function as an alternate retrieval channel for hidden or sensitive data.

For teams that need a broader reference point on access sprawl and exposed secrets, NHI Mgmt Group’s Ultimate Guide to Non-Human Identities is useful background on why hidden access paths and overbroad reach create material exposure.

What practitioners should verify before treating a shared report as safe

Start by checking whether the report, the semantic model, and any linked data sources share the same audience. If the report is intended for one group but the model is reusable by a wider set of users, the report is not the true control point. Also verify whether Q&A is enabled, whether excluded fields remain in the model, and whether row- or object-level restrictions actually apply at query time rather than only in the visual layer.

It is also worth validating what happens when the report is shared through broader links or inherited workspace access. The practical question is not whether the dashboard looks sparse, but whether the recipient can still ask the model for data the author believed was hidden. If yes, the access design needs to be tightened at the model or source layer, not just in the report layout.

For implementation detail around least-privilege exposure and hidden credential or data paths, NHI Mgmt Group’s Guide to the Secret Sprawl Challenge helps frame why surface-level restrictions can miss the real exposure point. For a broader control lens, the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls both reinforce that access boundaries need to be enforced where the data is actually reachable, not just where it is displayed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementControls who can query shared data models and report assets.
Recommendation — Restrict model and report access to approved audiences and review shared-link reach.
NIST CSF 2.0PR.AC — Access ControlShared reports expose data when access boundaries differ from the visible report.
PR.DS — Data SecurityThe risk is unintended disclosure of underlying data through a shared analytical model.
Recommendation — Enforce access controls at the data model and workspace layers. Protect sensitive fields and queryable data with least-privilege exposure limits.
OWASP Non-Human Identity Top 10NHI-03 — Overprivileged and Overexposed IdentitiesBroader query access can expose more data than the visible report implies.
Recommendation — Minimize shared access paths that let users query beyond intended report scope.

Practitioner Guidance

What to prioritise: Treat the semantic model as the primary asset when a Fabric report is shared. If the model contains sensitive fields, measures, or relationships, assume the report view alone is not an adequate protection boundary.

What to verify: Confirm who can query the model directly, whether Q&A is enabled, and whether report sharing expands access beyond the intended audience. The decisive test is whether a recipient can retrieve excluded values through the model even when they are absent from the visible report.

Common mistake: Teams often lock down the page layout and assume that means the data is protected. In this scenario, the visible report is only a presentation surface, so the control must be enforced at the data model, permission, and sharing layers.

Practitioner takeaway: If users can query the same semantic model that powers the report, then “restricted-looking” is not the same as restricted, and the security decision must be made on the underlying query path.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org