Holders can look at workspace content and query data via warehouses or SQL analytics endpoints, yet can't change anything. Semantic model RLS and OLS apply to them. It's the lowest-privilege workspace role.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Viewer in context, with comparison tables and the common traps.
Terms in this definition
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Semantic model
Sometimes called an OLAP model, this Power BI and Fabric layer defines the measures, hierarchies, tables and relationships that reports and dashboards query; star schema design is the usual pattern.
- RLS
Row-level security: filtering the data each person can see down to permitted rows. Power BI models apply it through DAX rules on roles, which bind just Viewers and anyone holding Read or Build; Fabric Warehouse instead uses a T-SQL policy that calls a predicate function.
- Object-level security
A semantic model feature that conceals entire tables or columns from a role's members, so they can't even see what exists; it is configured through TMDL view or Tabular Editor. For a SQL database the same term means object permissions set with GRANT and DENY.
- APPLY
Evaluates a table-valued expression for every row on its left, inside
FROM. Think ofOUTER APPLYas a left outer join andCROSS APPLYas an inner join. - Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
Related terms
- Active Directory Administrative Center
Includes a viewer showing the PowerShell behind each action, fine-grained password policy management and Recycle Bin restores; a Windows Server console for Active Directory built on PowerShell.
- Admin monitoring workspace
A preview workspace for Fabric admins that appears automatically when an admin first visits Admin monitoring under Workspaces. Its data is read-only and refreshed daily, powering reports like the Govern report in the OneLake catalog, and admins can give others access with the Viewer role.
- Content Explorer Content Viewer
Grants the ability to read what is inside items listed in the Content and Data explorers, plus AI prompts and responses shown in DSPM. List Viewer membership does not include this.
- Data explorer
Lists, in Microsoft Purview, every item currently tagged with a sensitivity or retention label or containing a sensitive information type, together with where it sits. To open those items, an admin needs membership of two role groups: List viewer and Content viewer.
- Dynamic M query parameters
Connects a column in the model with an M parameter, so that when a viewer picks something in a slicer or filter, that choice is written into the DirectQuery source query. It can't be used alongside row-level security or aggregations.
- F64
Equal in compute to a P1, this Fabric capacity has 64 capacity units. From this size upwards, Power BI content can be opened by people with just a Free licence and the Viewer role.
- Fixed identity
With single sign-on off, a Direct Lake model can be bound to one explicit cloud credential, such as a workspace identity or service principal. Permissions, RLS and CLS are then evaluated for that credential, not per viewer, so readers need no rights on the underlying item.
- Microsoft Purview Information Protection client
A client that runs only on Windows and took over from the Azure Information Protection unified labeling client. It provides a labelling tool in File Explorer, an encrypted-file viewer, a PowerShell module and the scanner, but nothing inside Office apps.