Microsoft is giving away 50,000 FREE Microsoft Certification exam vouchers!
Enter the sweepstakes now!Preparing for a certification exam? Ask exam experts all your questions on May 15th. Register now.
Hi,
I am creating a service principal to use Power BI Service API and I am a bit confused with regards the difference between the different permission/scopes that can be granted to the API
does the Tenant.WriteReadAll permission includes all the other ones *.WriteReadll? I think so, but my tenant admin requires to clarify what is the purposed of the permission before to consent it.
Could I destroy something out of the Power BI Service (I mean for instance some Azure subscription group) scope with the Tenant.WriteReadAll permission given to the Power BI Service API?
(this is the message that the admin receives to consent)
Regards,
Solved! Go to Solution.
I see what you mean. Items outside the Power BI/Fabric scope. I don't think so.
Hi @alfBI
May I ask if you have resolved this issue? If so, please mark the helpful reply and accept it as the solution. This will be helpful for other community members who have similar problems to solve it faster.
Thank you.
Hi,
Checking the Power BI Rest API Docs I see that admin tasks Admin - REST API (Power BI Power BI REST APIs) | Microsoft Learn (that are the ones I assume included on the tenant.ReadWriteall) does not include anything such as removing a subscription, an Entry ID group or a virtual network .
Of course you can do dangerous things as assigning a capacity to a workspace but this is part of the power bi scope.
Do you have a sample of some potential action using the Power BI API Rest with the tenant.ReadWriteall permission that can impact a non-PowerBI/Fabric Item?
Many Thx
I see what you mean. Items outside the Power BI/Fabric scope. I don't think so.
Could I destroy something out of the Power BI Service (I mean for instance some Azure subscription group) scope with the Tenant.WriteReadAll permission given to the Power BI Service API?
yes, very much so. You need to have technical (documentation) and non-technical (legal threats) precautions in place when you grant that.
Check out the April 2025 Power BI update to learn about new features.
Explore and share Fabric Notebooks to boost Power BI insights in the new community notebooks gallery.
User | Count |
---|---|
38 | |
25 | |
22 | |
11 | |
10 |