Power BI is turning 10, and we’re marking the occasion with a special community challenge. Use your creativity to tell a story, uncover trends, or highlight something unexpected.
Get startedJoin us for an expert-led overview of the tools and concepts you'll need to become a Certified Power BI Data Analyst and pass exam PL-300. Register now.
Hi,
I am creating a service principal to use Power BI Service API and I am a bit confused with regards the difference between the different permission/scopes that can be granted to the API
does the Tenant.WriteReadAll permission includes all the other ones *.WriteReadll? I think so, but my tenant admin requires to clarify what is the purposed of the permission before to consent it.
Could I destroy something out of the Power BI Service (I mean for instance some Azure subscription group) scope with the Tenant.WriteReadAll permission given to the Power BI Service API?
(this is the message that the admin receives to consent)
Regards,
Solved! Go to Solution.
I see what you mean. Items outside the Power BI/Fabric scope. I don't think so.
Hi @alfBI
May I ask if you have resolved this issue? If so, please mark the helpful reply and accept it as the solution. This will be helpful for other community members who have similar problems to solve it faster.
Thank you.
Hi,
Checking the Power BI Rest API Docs I see that admin tasks Admin - REST API (Power BI Power BI REST APIs) | Microsoft Learn (that are the ones I assume included on the tenant.ReadWriteall) does not include anything such as removing a subscription, an Entry ID group or a virtual network .
Of course you can do dangerous things as assigning a capacity to a workspace but this is part of the power bi scope.
Do you have a sample of some potential action using the Power BI API Rest with the tenant.ReadWriteall permission that can impact a non-PowerBI/Fabric Item?
Many Thx
I see what you mean. Items outside the Power BI/Fabric scope. I don't think so.
Could I destroy something out of the Power BI Service (I mean for instance some Azure subscription group) scope with the Tenant.WriteReadAll permission given to the Power BI Service API?
yes, very much so. You need to have technical (documentation) and non-technical (legal threats) precautions in place when you grant that.
This is your chance to engage directly with the engineering team behind Fabric and Power BI. Share your experiences and shape the future.
Check out the June 2025 Power BI update to learn about new features.
User | Count |
---|---|
59 | |
35 | |
27 | |
26 | |
24 |
User | Count |
---|---|
62 | |
53 | |
30 | |
23 | |
20 |