← Back to postsHow Do You Access the Power BI Admin Portal? (2026 Guide)

How Do You Access the Power BI Admin Portal? (2026 Guide)

Carlos GarciaCarlos Garcia9/25/2026

Most Power BI questions that start with "why can't I" end in the admin portal. Why can't I publish to the web. Why can't I export this to Excel. Why can't anyone outside my department open the report I just shared. None of those are bugs. They are tenant settings, and tenant settings live in one screen that most Power BI users have never opened.

The confusion is understandable, because the portal moved. What used to be the Power BI admin portal is now the Microsoft Fabric admin portal, reached from the Fabric settings menu rather than from anywhere obviously labelled "Power BI". The Power BI content is still all there, but the door is in a different wall.

This guide covers the exact click path, the roles that get you in, what each section of the portal actually controls, and the handful of gotchas that waste the most time once you are inside.

How Do You Access the Power BI Admin Portal?

Open the Fabric portal in a browser, select the settings gear at the top right, then choose Admin portal under the Governance and insights heading in the side pane that opens.

That is the whole path. There is no separate admin URL to memorise and no desktop application involved. Power BI Desktop has nothing to do with it; administration is entirely a service-side activity, so you need a browser and a signed-in account with the right role.

Once the portal opens, the left-hand navigation lists every available section. Tenant settings is where most people are heading, and it is usually the first item on that list.

Step by step, from a cold start:

  1. Go to the Fabric portal at app.fabric.microsoft.com and sign in with your work account.
  2. Select the settings (gear) icon in the top-right corner of the header bar.
  3. In the side pane, find the Governance and insights heading and select Admin portal.
  4. Choose the section you need from the left-hand navigation, most often Tenant settings.

If you get there and see only a single item called Capacity settings, the portal has loaded correctly and your account simply does not hold an admin role. That is the normal experience for a capacity admin or an ordinary user, and it is the clearest signal you will get that you need someone else to make the change.

Not sure whether your reporting content is actually being found? Get a free SEO audit and see where you stand.

Who Can Open the Admin Portal?

Access is controlled by role, not by licence tier alone. You need both a Fabric licence and an admin role assigned in Microsoft Entra ID or the Microsoft 365 admin center. A Power BI Pro licence on its own gets you nothing here.

Fabric administrator

This is the role most people mean when they say "Power BI admin". It grants full access to the admin portal, including every tenant setting, capacity management, domains, workspace oversight and the organisational visuals and themes catalogues.

The role was formerly called Power BI administrator and was renamed as Fabric absorbed Power BI's administration surface. If you are following older documentation or an internal runbook written before the rename, assume the two names refer to the same thing.

One practical consequence of the rename catches people out during audits: the role you are looking for in Entra ID may appear under either label depending on when your tenant was provisioned and how your directory surfaces built-in roles. Search for both before concluding that nobody holds it.

Power Platform administrator and Global administrator

Both of these inherit Fabric administration rights. A Power Platform administrator holds Fabric responsibilities as part of a wider Power Platform remit, and a Microsoft 365 Global administrator has broad access across every workload including this one.

In practice, granting Global administrator to solve a Power BI problem is a bad trade. It is a far wider permission than the task needs, and Fabric administrator exists precisely so that you do not have to hand out tenant-wide control to change an export setting.

Capacity admins, domain admins and everyone else

A capacity admin manages specific F, P, EM or A capacities and sees only the capacity settings page. A domain admin manages a named business domain and the workspaces assigned to it. A workspace admin controls one workspace and does not appear in the admin portal at all.

These narrower roles exist for delegation, and they are the right answer in most large organisations. Give a data platform team capacity admin rather than Fabric admin, and the blast radius of a mistake stays small.

The delegation model also keeps the change queue moving. When only two people in a company of two thousand can touch anything, every routine capacity adjustment becomes a ticket, and the tenant settings that should be reviewed quarterly get reviewed once and never again.

Curious how your competitors are showing up in AI search results? Get a free SEO audit and find out.

What Is Actually Inside the Admin Portal?

The portal is a set of pages rather than one settings screen, and knowing which page owns which problem saves a lot of scrolling.

Tenant settings is the largest section by far. It enables, disables and scopes platform features across the whole organisation: export and sharing behaviour, publish-to-web, developer and API settings, workspace creation rights, AI features, and dozens more. Each setting can be applied to everyone, to nobody, or to named security groups.

Capacity settings manages Fabric F capacities, Power BI Premium P capacities and Embedded EM and A capacities, including who administers each one and how workloads are allocated.

This is also where you assign capacity admins, which is the single most useful piece of delegation available to a Fabric administrator who does not want to be the bottleneck for every performance question.

Workspaces gives a tenant-wide view of every workspace, its type, its state and who owns it. This is the fastest way to find orphaned workspaces after someone leaves.

Domains organises workspaces into business domains so that governance and discovery can be delegated by business area rather than by IT structure.

Embed codes lists every publish-to-web code that exists in the tenant, with the option to revoke any of them. If you ever inherit an unfamiliar tenant, this page is worth opening on day one.

Organisational visuals and organisational themes control which custom visuals and report themes your users can reach, which is how you keep a marketplace visual out of production without blocking the whole marketplace.

Refresh summary, Azure connections, workloads, tags, custom branding, Fabric identities and featured content round out the list. Users and audit logs appear too, but both are signposts: users are managed in the Microsoft 365 admin center, and audit logs are read in the Microsoft Purview portal.

The list is not static. Microsoft adds pages as Fabric absorbs more workloads, so a section that is missing from a guide written six months ago may well be sitting in your portal today. Treat the left-hand navigation in your own tenant as the authoritative inventory rather than any article, including this one.

How Do You Change a Tenant Setting?

Open Tenant settings, use the search box at the top rather than scrolling, expand the setting you want, then choose how widely it applies.

Every tenant setting supports five states, and the distinction between them matters more than the on/off toggle suggests:

  • Disabled for the entire organisation, so nobody can use the feature.
  • Enabled for the entire organisation, so everybody can.
  • Enabled for the whole organisation except specific security groups.
  • Enabled only for specific security groups.
  • Enabled for specific groups but excluding certain groups within them.

Where an allow rule and a deny rule both apply to the same person, the most restrictive rule wins. That is the behaviour to reason from when someone insists they should have access and does not.

Select Apply when you are done. Changes are not instant: Microsoft's guidance is that a setting change can take up to fifteen minutes to reach everyone in the organisation. Do not spend that quarter of an hour convinced the change failed.

Want to know which pages on your site AI assistants are actually reading? Get a free SEO audit to find out.

When Do You Actually Need the Admin Portal?

Most of the time, you do not. Sharing a report, creating a workspace and scheduling a refresh are all workspace-level activities that need no admin involvement at all.

You need the portal when the answer to a problem is organisation-wide. Somebody cannot export data to Excel and nobody else can either. A team needs publish-to-web for a public dashboard. A custom visual has to be approved before finance will use it. An auditor wants a list of every workspace in the tenant.

The other recurring trigger is onboarding and offboarding at the platform level. When a new business unit arrives, someone has to decide which domain its workspaces belong to, which capacity carries its load, and which tenant settings its security group should be added to.

Security reviews are the third. An auditor asking how your organisation controls publishing to the public internet is asking about a tenant setting and the embed codes page, and both answers come from the admin portal rather than from any individual report.

If your question is about one report, one dataset or one person's access, the admin portal is almost certainly the wrong place to look. Start with the workspace role assignments instead.

What the Admin Portal Will Not Do

It is not a security boundary. Microsoft is explicit about this, and it is the single most misread aspect of tenant settings. Turning off "export data" does not stop a user with read access from querying the underlying semantic model through another route. Tenant settings govern feature availability in the interface, not data access.

It does not manage users. The Users page sends you to the Microsoft 365 admin center, because licences and accounts are Microsoft 365 objects rather than Fabric ones.

It does not show you audit data directly either. Audit logs are surfaced in Microsoft Purview, and the admin portal simply points you there.

It also cannot grant itself. If you do not hold an admin role, no amount of navigating will reveal the missing pages; you will see capacity settings and nothing else. The fix is an Entra ID role assignment made by someone who already has one.

And it keeps no built-in change history you can browse. If you need to know who turned a setting off last quarter, that record lives in the audit log in Purview, not in the portal itself, which is a good reason to write down tenant setting changes somewhere your team will actually look.

Finally, changes here are tenant-wide by default. A setting flipped to prove a point at 4pm on a Friday affects every user in the organisation fifteen minutes later. Scope to a security group when you are testing.

Admin Portal vs the Other Ways to Administer Power BI

The portal is the interactive option, and it is the right one for exploratory work and one-off changes. It is not the only one.

The Fabric and Power BI REST APIs expose much of the same surface programmatically, including tenant settings, workspace inventory and capacity assignment. If you need a nightly export of every workspace and its owners, that is an API job, not a portal job.

PowerShell modules wrap those APIs and suit administrators who already script the rest of their Microsoft estate. Bulk operations across hundreds of workspaces are far less painful this way.

The Microsoft 365 admin center owns users, groups and licences, and Microsoft Purview owns audit and compliance reporting. Both sit alongside the admin portal rather than underneath it, which is why the portal links out to them instead of duplicating them.

A reasonable division of labour: use the portal to decide policy, use the APIs to enforce and report on it.

That split scales in a way that clicking does not. Policy decisions are rare and benefit from a human looking at a screen; inventory, drift detection and reporting happen constantly and should never depend on somebody remembering to open a page.

Ready to see how your site performs in traditional and AI search? Get a free SEO audit today.

Final Thoughts

The Power BI admin portal is not hard to use once you know it is a Fabric screen reached through the settings gear, that access depends on holding the Fabric administrator role rather than a Pro licence, and that most of what you want is behind the tenant settings search box.

The two habits worth building are scoping changes to security groups instead of the whole organisation, and waiting the full fifteen minutes before deciding a change did not work. Between them they prevent most admin-portal frustration.

If you are still mapping out how the service side of Power BI fits together, our guide to what the Power BI service actually is covers the layer the admin portal governs, and makes the tenant settings list a lot easier to read.