FREE STUDY NOTES · DP-600

Microsoft Fabric workspace roles: Admin, Member, Contributor and Viewer

What each Fabric workspace role can do across Power BI, data engineering, warehousing and real-time items.

From Ultra Transcenders DP-600 by Tony Rough (coming December 2026)

Workspace roles are Admin, Member, Contributor and Viewer. Fabric extends the original Power BI roles with data engineering, warehousing and real-time capabilities, so the capability matrix is the core of this objective.

Fabric capability matrix

Capability Admin Member Contributor Viewer
Update and delete the workspace Yes No No No
Add or remove people, including other admins Yes No No No
Add members or others with lower permissions Yes Yes No No
Allow others to reshare items Yes Yes No No
Create a workspace identity Yes No No No
Connect the workspace to a Git repository Yes No No No
Create or modify warehouse, database and mirrored database items Yes Yes Yes No
Write or delete pipelines, notebooks, Spark job definitions, eventstreams, eventhouses, KQL querysets, lakehouse and warehouse data, shortcuts Yes Yes Yes No
Execute or cancel notebooks, Spark job definitions and pipelines Yes Yes Yes No
Connect to the SQL analytics endpoint or warehouse Yes Yes Yes Yes
Read lakehouse and warehouse data with T-SQL (ReadData) Yes Yes Yes Yes
Read lakehouse and warehouse data through Spark and OneLake APIs, or the Lakehouse explorer (ReadAll) Yes Yes Yes No
Subscribe to OneLake events Yes Yes Yes No
View pipeline, notebook and experiment content and execution output Yes Yes Yes Yes
Schedule refreshes through an on-premises gateway, modify gateway connection settings Yes Yes Yes No

Shortcut data and gateway operations also need permissions on the shortcut target or the gateway, which are managed separately from workspace roles.

Power BI capabilities by role

Capability Admin Member Contributor Viewer
Publish, unpublish and change permissions for an app Yes Yes No No
Update an app Yes Yes If the Admin allows it No
Share items, including semantic models, and allow resharing Yes Yes With Reshare With Reshare
Create, edit and delete content Yes Yes Yes No
Build a report in another workspace on a semantic model here Yes Yes Yes No
Analyze in Excel, download a PBIX Yes Yes Yes No (Viewers need Build for Analyze in Excel)
Manage subscriptions created by others Yes No No No
View and interact with items Yes Yes Yes Yes

How role assignment behaves

Common trap: Giving a Member the job of connecting the workspace to Git or creating a workspace identity - both are Admin-only actions.

Common trap: Expecting Viewers to explore a lakehouse in a notebook - Viewers can read through the SQL analytics endpoint (ReadData) but not through Spark, OneLake APIs or the Lakehouse explorer (ReadAll), unless a OneLake security role or item permission grants it.

Common trap: Asking a Member to promote a Viewer to Contributor - Members can add people with the same or lower role but can’t change existing users’ roles.

Get the whole book

This note is one section of Ultra Transcenders DP-600: Implementing Analytics Solutions Using Microsoft Fabric, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · DP-600 terms in the glossary · All DP-600 study notes

More DP-600 study notes