Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Get Fabric certified for FREE! Don't miss your chance! Learn more

Reply
Kiwi_Mark_LFC
Frequent Visitor

Are MS going to make Power BI suitable for Enterprise Audiences

Because we cant control user access to this in the App

Kiwi_Mark_LFC_0-1765247560036.png

Or this

Kiwi_Mark_LFC_1-1765247589099.png

 

Users can access options we may not want them to

 

Why is Power BI not designed for an Enterprise Environment?

1 ACCEPTED SOLUTION

Hello @Kiwi_Mark_LFC ,

 

I understand your perspective, and while we may not agree on the conclusion, we are on the same page regarding the facts. There is no confusion about Fabric’s behavior or its configuration. The behavior you mentioned is how the product currently works, and there isn’t a hidden setting or undocumented method to change it.

Microsoft’s definition of enterprise in Fabric centers on aspects like scale, identity integration, compliance, auditing, data security, and governance, rather than customizing the SaaS portal UI for different user views. Some organizations may have a different view of enterprise readiness, and it’s reasonable to disagree, but this is a deliberate product decision rather than a limitation in understanding or capability.

Because of this design, the Fabric portal will always show the full product interface to licensed users, including those meant to be view-only. Their permissions control access and changes, but the interface itself isn’t part of the security model. For organizations that need to restrict visibility, the native portal may not be suitable, and embedded analytics is the only way to fully control the user experience.

At this time, there is no technical solution other than confirming this limitation and acknowledging your feedback. Your concern is valid as a product critique, but it cannot be addressed through current configuration or documentation in Fabric.

Thank you.

View solution in original post

9 REPLIES 9
nielsvdc
Super User
Super User

Hi @Kiwi_Mark_LFC, when you think Fabric is not an Enterprise solution, you might need a bit more training in Fabric. Fabric is build with the integrated security of Microsoft Entra ID on all levels.

 

Assigning user permissions is not done within the report interface. You can assign user access permissions using the following methods.

  1. Use org apps, is the best way to give your view only users access to one or more reports in a single interface.
  2. Give users access through a workspace role. This is more suitable for people who manage or create reports, although this method also support view-only permissions. Also read more about roles in workspaces.
  3. Another way is to share a report with a direct item-level link. This is an optional way of providing access to a specific report to users, when the don't have access to a report through org app or workspace permissions.

The main requirement for users to be able to view reports, is that they have to have a Fabric license assign to them. In small organizations this is done by assigning users a Pro license and in Enterprise organizations view-only users might have a free license, depending on the Fabric capacity size used in the organization.

 

Hope this helps getting started with sharing your reports. If so, please give kudos 👍 and mark as Accepted Solution ✔️ to help others.

I know all that - that is not what I was pointing out - I was pointing out that you CANNOT restrict what parts of Power BI/Fabric a user has access to

 

Perhaps you need to take some training

 

You give them access to a workspace and they can play with a whole raft of things they should not be anywhere near

 

And the ability to control that is extremely limited (and what control their is is beyond clunky)

 

So again - Fabric is NOT designed for Enterprise (at least not correctly and completely)

 

And dont get me started on the ABYSMAL deployment pipelines

 

There is VERY LITTLE in Fabric that actually works for a PROPER and CORRECT enterprise solution

 

Just because it uses MS Entra ID and Azure AD Groups does NOT make it an Enterprise Solution - if you think thats all that is required to make something Enterprise then I would never hire you

 

This is the trouble with MS and Fabric/Power BI - riddled with amateurs who havent a clue 

Hi @Kiwi_Mark_LFC ,

 

I appreciate your observations regarding Fabric’s limitations. You are correct that once a user is granted authoring access to a workspace, Fabric does not provide granular restrictions on individual features or experiences. This is an intentional design decision rather than an oversight or lack of configuration options.

 

Fabric’s approach to security and governance is centered around identity, data, and item-level controls, rather than limiting access to specific parts of the interface. Authoring roles are intended for trusted users, so partial restrictions within workspaces are not enforced. As a result, business users with workspace access may have more capabilities than some organizations prefer.

 

The recommended enterprise model is to maintain strict separation of roles, with consumers accessing content through apps or view-only sharing, and avoiding workspace access. Workspaces are meant for developers and administrators. When these boundaries are not observed, governance can become challenging.

 

Regarding deployment pipelines, your feedback is valid. While Fabric pipelines offer convenience, they do not provide comprehensive enterprise ALM functionality, and many organizations supplement them with external CI/CD tools and processes.

 

In summary, Fabric is designed for enterprise use with a focus on clear authoring roles and controlled content distribution. However, if fine-grained UI restrictions within workspaces are required, it may not fully align with those needs.

Thank you.

Hi @Kiwi_Mark_LFC ,

 

I wanted to follow up and see if you had a chance to review the information shared. If you have any further questions or need additional assistance, feel free to reach out.

 

Thank you.

"Fabric’s approach to security and governance is centered around identity, data, and item-level controls, rather than limiting access to specific parts of the interface. Authoring roles are intended for trusted users, so partial restrictions within workspaces are not enforced. As a result, business users with workspace access may have more capabilities than some organizations prefer."

 

This is so incorrect - Users have access to numerous Activities/Features in Fabric/Power BI whether they have access to a Workspace or not

 

So how does one restrict view users from accessing other parts of the Fabric/Power BI UI then - because I cant see how this can be done - you either give them access to a workspace or an app - and neither allows restricting access to elements you dont want a user to have (unless you use embedded)

 

This is what a normal View user sees

 

When they Login

Kiwi_Mark_LFC_0-1766037294775.png

 

From the App

Kiwi_Mark_LFC_2-1766037374775.png

 

Kiwi_Mark_LFC_1-1766037341799.png

 

We dont want them having access to any of this - this should not be MS choice - this is not Enterprise

 

I cannot find any documentation on how to limit this

 

There is massive blurring of the lines between authoring and viewing - regardless of workspace access or not - you statement is factually incorrect

 

Users should ONLY be allowed to ACCESS the Activities/Features/etc WE decide - not MS

 

This is NOT enterprise

 

MS has never understood enterprise and prob. never will

 

And it seems no one on these forums do either

Hi @Kiwi_Mark_LFC ,

 

In Fabric and Power BI, all licensed and authenticated users will land on the Fabric portal and see the global navigation when they sign in, whether they only use an app or don’t have workspace access. There is no supported way to hide these portal areas or activities for view users; this is a product limitation, not a configuration issue, and it is not documented. Users can see sections like Workspaces or Browse, but only have access to permitted content and are restricted from authoring or admin actions. Security is managed through identity, tenant settings, licenses, and item-level permissions, rather than customizing the portal interface for each user.

 

If your organization needs users to interact with only one governed interface and not the broader Fabric experience, the native Fabric portal does not support this. The only supported solution for full UI control is Power BI Embedded, where the hosting app determines what users can see and do. While feedback on making this a customer-controlled option is valued, Fabric currently does not offer further UI restrictions beyond tenant-level settings and permissions.

Thank you.

Yes - I know all that - thats my point

 

MS Have ZERO CLUE as to what constitutes an ENTERPRISE solution

 

As it appears noone on this forum does either

 

And level of reading comprehension is below that of a 4th grader

Hello @Kiwi_Mark_LFC ,

 

I understand your perspective, and while we may not agree on the conclusion, we are on the same page regarding the facts. There is no confusion about Fabric’s behavior or its configuration. The behavior you mentioned is how the product currently works, and there isn’t a hidden setting or undocumented method to change it.

Microsoft’s definition of enterprise in Fabric centers on aspects like scale, identity integration, compliance, auditing, data security, and governance, rather than customizing the SaaS portal UI for different user views. Some organizations may have a different view of enterprise readiness, and it’s reasonable to disagree, but this is a deliberate product decision rather than a limitation in understanding or capability.

Because of this design, the Fabric portal will always show the full product interface to licensed users, including those meant to be view-only. Their permissions control access and changes, but the interface itself isn’t part of the security model. For organizations that need to restrict visibility, the native portal may not be suitable, and embedded analytics is the only way to fully control the user experience.

At this time, there is no technical solution other than confirming this limitation and acknowledging your feedback. Your concern is valid as a product critique, but it cannot be addressed through current configuration or documentation in Fabric.

Thank you.

Hi @Kiwi_Mark_LFC ,

 

I wanted to check if you had the opportunity to review the information provided. Please feel free to contact us if you have any further questions.

Thank you.

Helpful resources

Announcements
Sticker Challenge 2026 Carousel

Join our Community Sticker Challenge 2026

If you love stickers, then you will definitely want to check out our Community Sticker Challenge!

Free Fabric Certifications

Free Fabric Certifications

Get Fabric certified for free! Don't miss your chance.

January Fabric Update Carousel

Fabric Monthly Update - January 2026

Check out the January 2026 Fabric update to learn about new features.

FabCon Atlanta 2026 carousel

FabCon Atlanta 2026

Join us at FabCon Atlanta, March 16-20, for the ultimate Fabric, Power BI, AI and SQL community-led event. Save $200 with code FABCOMM.