Forum Discussion

ifeanyi's avatar
ifeanyi
Frequent Visitor
1 year ago
Solved

User with Contributor Role Unable to Checkout Branches or Create New Workspaces

I recently created a Microsoft Fabric workspace and added a user with the Contributor role. The workspace is connected to an Azure DevOps repository. However, we noticed that the user is unable to perform certain actions, specifically:

  1. Checkout a branch

  2. Branch out to a new workspace

These options remain disabled for the user as shown in the image below.

 

 

Interestingly, when I change the user’s role from Contributor to Admin, the options become available, and the user can perform the actions without any issues.

Has anyone encountered a similar situation? Is this expected behavior for the Contributor role, or could there be a configuration issue? Additionally, could the integration with the Azure DevOps repository be impacting these permissions?

Any insights or suggestions would be greatly appreciated.

Thank you in advance!

  • Hi ifeanyi 

     

    • Thank you for sharing your thoughtful workaround for managing least-privilege access in Microsoft Fabric.

    • We understand the current limitations around granular role-based permissions, especially compared to Synapse or Data Factory.

    • Using a dedicated collaboration workspace to isolate contributor access is a practical and effective solution.

    In the meantime, if you're open to it, we recommend sharing your approach and suggestions on the Fabric Ideas - Microsoft Fabric Community It’s actively reviewed by the product team and helps influence future roadmap priorities.

    Let us know if you’d like assistance with anything else or help streamlining your current setup further.

     
    Thanks for being a part of Microsoft Fabric Community Forum.

19 Replies

  • We are seeing similar things all of the sudden since a week or so.

    No clear update/change can be found on any summary by Microsoft about roles, so no clue what happened.

    We tested previously with contributor role and commiting and updating worked fine, now it doesn't anymore.
    We had to change the users to admins, this cannot be the way to go.

     

    Looking forward to what real solution will be provided here...

  • Hello ifeanyi 

     

    This is expected behaviour. 

    The Contributor role in Microsoft Fabric allows users to view and modify content within a workspace but does not include permissions for managing workspace settings or advanced configurations like Git integration. These capabilities are typically reserved for Members and Admins

     

    Members can perform tasks such as sharing content, adding users with lower permissions, and managing some workspace settings, while Admins have full control over workspace management, including permissions and configurations

    https://learn.microsoft.com/en-us/fabric/security/permission-model

     

    Please accept this answer and give kudos if this is helpful 

    • ifeanyi's avatar
      ifeanyi
      Frequent Visitor

      Hi nilendraFabric ,

      Thank you for your response. I understand that Contributors have limited permissions compared to Members and Admins. However, the Microsoft Fabric Git integration documentation suggests Contributors should be able to checkout branches and create workspaces as part of the Git workflow.

       

      Could there be additional settings or restrictions causing this, or is the documentation outdated? I’d appreciate further clarification.

       

      Thanks again!

      • nilendraFabric's avatar
        nilendraFabric
        Super User

        Hello ifeanyi 

         

         

        Contributor role can pull updates from Git (“Update from Git”) and push or commit changes (“Commit workspace changes to Git”) only if they have full WRITE rights on all items that need modification. This means:
        • The user must be granted the Contributor role in the workspace.
        • Their corresponding Git repository permissions should be set to allow both reading (Read=Allow) and contributing (Contribute=Allow) changes.
        • Additionally, branch policies must be configured to permit direct commits. If the branch has requirements like pull requests or other controls, those rules must be respected, and direct commits might not be allowed.

         

        see if this is all done and then test it. 

         

  • ifeanyi's avatar
    ifeanyi
    Frequent Visitor

    I am the administrator of a Microsoft Fabric workspace connected to an Azure DevOps repository, and I have encountered an issue with user permissions. Specifically, when adding a user with Contributor access, they are unable to perform the following actions:

    • Check out a branch
    • Create a new branch from the workspace

    These options remain disabled for the user, as shown in the attached image.


     

    However, when I update their role to Member, the options become enabled, allowing them to create a branch. Unfortunately, an error occurs during the process (details in the attached image).

     

     

    When I further upgrade their role to Admin, they can successfully check out and create a new branch without any issues.

     

    I want to adhere to the principle of least privilege, meaning I do not want users to have Admin access unless absolutely necessary. Ideally, I would like them to perform these actions as Contributors. Could you please confirm whether this is expected behavior or if there is a configuration setting that needs adjustment?

     

    Your guidance on resolving this would be greatly appreciated.

     

    Thank you in advance for your support!

  • hernandezpaulms's avatar
    hernandezpaulms
    Microsoft Employee

    I'm curious about your strategies for overcoming this limitation. Personally, I find it quite frustrating that a Workspace member or contributor cannot create a new branch—something that's possible in Synapse or Data Factory workspaces. Assigning the Workspace Admin role feels too elevated and doesn't align with a least privilege approach.

    • ifeanyi's avatar
      ifeanyi
      Frequent Visitor

      You're absolutely right—this limitation can be quite frustrating, especially when trying to maintain a least-privilege access model. It's not as straightforward as it is in Synapse or Data Factory.

      To work around this, we’ve adopted a mitigation strategy by introducing an intermediary collaboration workspace. Here's how we approach it:

      We start with a primary workspace, for example, contoso_wsp[Dev]. As an admin, I create a secondary workspace named contoso_collaboration_wsp. I then assign contributor users as admins to this collaboration workspace—not to the original one. This setup gives them the permissions needed to create their own development branches or workspaces (e.g., contoso_collaboration_wsp_contributor1, contoso_collaboration_wsp_contributor2, etc.).

      Once their work is complete, I review and merge changes from these contributor workspaces back into the main contoso_wsp [Dev].

      While it’s a bit of an overhead and certainly not ideal, this structure helps us maintain control over the dev environment while enabling contributor-level users to work independently.

      That said, I’d be keen to hear how others are overcoming this challenge and whether there are any updates on how Microsoft Fabric plans to mature its support for DevOps/DataOps and CI/CD workflows.

      • v-aatheeque's avatar
        v-aatheeque
        Community Support

        Hi ifeanyi 

         

        • Thank you for sharing your thoughtful workaround for managing least-privilege access in Microsoft Fabric.

        • We understand the current limitations around granular role-based permissions, especially compared to Synapse or Data Factory.

        • Using a dedicated collaboration workspace to isolate contributor access is a practical and effective solution.

        In the meantime, if you're open to it, we recommend sharing your approach and suggestions on the Fabric Ideas - Microsoft Fabric Community It’s actively reviewed by the product team and helps influence future roadmap priorities.

        Let us know if you’d like assistance with anything else or help streamlining your current setup further.

         
        Thanks for being a part of Microsoft Fabric Community Forum.