Ensure 'Interact with and share R and Python' visuals is 'Disabled'
Why This Matters
R and Python visuals in Power BI allow users to run custom scripts embedded in reports, which can execute arbitrary code on the service. Disabling this feature reduces the risk of malicious code execution that could lead to data breaches, unauthorized access, or leakage of confidential information. IT administrators should prioritize this control to prevent untrusted scripts from operating within their Power BI environment.
What Aether365 Checks
Aether365 verifies that the "Interact with and share R and Python visuals" setting in the Power BI tenant admin portal is set to "Disabled". This check appears in the Aether365 dashboard under Microsoft 365 security checks.