Back to all posts

Fabric IQ MCP Is GA. Can Your Clients Use It? (Power BI MCP Servers Explained)

Fabric IQ MCP is generally available. What the Power BI MCP servers do, what they need, and why no service principal support means it can't sit behind app-owns-data client reporting.

Fabric IQ MCP is Microsoft's generally available MCP server for Power BI. Any MCP-compatible AI agent can use it to find reports, read semantic model schemas and run DAX, with row-level security intact. It only accepts delegated sign-in with a Microsoft Entra work or school account. Service principal and app-only authentication aren't supported. That makes it a tool for people inside your tenant, not for the external viewers of an app-owns-data client portal.

Fabric IQ MCP is the best thing Microsoft shipped for Power BI developers this year. Point Claude, GitHub Copilot or your own agent at it and it answers questions from your semantic models. It doesn't even need the model to sit on Fabric or Premium capacity. Now read the authentication section. Delegated sign-in only, Entra work or school account only, and one blunt line: service principal and application-only authentication aren't supported. If you deliver client reporting through app-owns-data embedding, that one line is the whole story. Here's what the MCP servers do, what they need, and where the wall is.

TL;DR

  • Fabric IQ MCP is GA. It's a remote, read-only MCP server with six tools for Power BI reports and semantic models.
  • It doesn't answer questions by itself. Your AI agent picks the tools, writes the DAX and explains the result.
  • Auth is delegated OAuth through Entra ID. No service principal, no app-only auth.
  • RLS and OLS apply to the signed-in user. Different users can get different answers to the same query.
  • Client portals run on app-owns-data, where a service principal renders reports for viewers who have no account in your tenant. Fabric IQ MCP can't work that way, by design.
  • For external viewers you need AI that runs in the embedding layer, not in the viewer's Microsoft identity.
  • The DataTako MCP server is coming soon: MCP access for portal viewers, under their own RLS, without an Entra account in your tenant.

What is MCP, in one paragraph?

The Model Context Protocol (MCP) is an open standard that lets an AI agent call external tools in a predictable way. An MCP server publishes a list of tools ("search reports", "run this query") and the agent decides which ones to call. For Power BI, that means an agent like Claude or GitHub Copilot can look up a semantic model, read its schema and query it, without you building a custom integration for each AI client.

Which Power BI MCP servers exist?

Microsoft now documents three, and the naming has changed during 2026, so it's worth being precise.

  • Fabric IQ (MCP). The consumption layer. Answers business questions over governed Power BI data, read-only. Generally available. Endpoint: https://fabriciq.svc.cloud.microsoft/v1/mcp/fabriciq.
  • Power BI Authoring MCP server. For building models: create and change tables, columns, measures, relationships, calculation groups and security roles, run bulk refactors, check best practices. Available hosted (Microsoft-managed) and local (runs on your machine). Microsoft is explicit that you shouldn't use it for consumption: "it isn't designed to answer business questions for end users."
  • Power BI Consumption MCP server. The earlier query endpoint, often called the "remote MCP server" in coverage from early 2026. Still documented for existing integrations, but Microsoft now points new consumption scenarios to Fabric IQ.

If you read an MCP article from the first half of 2026, it's probably describing the Consumption server. For anything new, Fabric IQ is the one to use.

What can Fabric IQ MCP actually do?

It exposes six read-only tools:

The six Fabric IQ MCP tools

Tool What it does
DiscoverArtifacts Searches for reports and semantic models by name
ResolveFabricItem Resolves a Fabric item URL for the other tools
GetReportMetadata Reads report metadata
GetSemanticModelSchema Reads the model schema
ValueSearch Finds specific stored values in a model
ExecuteQuery Runs a DAX query against one semantic model
All six tools are read-only. The calling AI agent picks the tools, writes the DAX and explains the result. Source: Microsoft Learn, Fabric IQ MCP (checked 30 September 2026).

The important detail: Fabric IQ MCP has no natural-language answering tool. The agent calling it does the reasoning. It discovers the model, reads the schema, writes DAX, runs it and explains the result. Microsoft publishes a Fabric IQ skill that teaches agents how to do that well. So the quality of the answer depends as much on your agent and your model's naming as on Microsoft.

A few limits worth knowing before you build on it:

  • One semantic model per ExecuteQuery. No joins across models.
  • 250 rows by default. Larger results come back as a CSV resource, still subject to Power BI query limits.
  • Results are only as fresh as the last successful refresh.
  • Not supported: dashboards, paginated reports, Power BI apps, Fabric ontologies and data agents.
  • Not available in Power BI-only regions or sovereign clouds.
  • Reports and semantic models don't need to be on Fabric or Premium capacity.

How does Fabric IQ MCP authenticate?

Delegated OAuth 2.0 through Microsoft Entra ID, with a work or school account. The client needs three delegated Power BI API permissions: Item.Read.All, Item.Execute.All and Dataset.Read.All. By default users can consent to these themselves, unless your admin restricts consent.

Two things follow from that:

  1. It sees what the user sees. Microsoft: "Connecting through MCP doesn't grant access to reports, semantic models, or data that the caller can't otherwise access." RLS and OLS keep filtering. You don't even need a workspace role or Build permission, just access to the report or model.
  2. There is no service principal route. The docs state it plainly: "Service-principal and application-only authentication aren't supported." Every call is made as a real, signed-in person.

Why does "no service principal" rule out client portals?

Because that's how client portals work. Almost every Power BI client portal, ours included, uses app-owns-data embedding. Your application authenticates to Power BI as a service principal and generates an embed token for each viewer. The token carries an effective identity, so RLS filters to that viewer's data. The viewer never signs in to your Microsoft tenant, never needs a Pro licence and never has an Entra account with you. (More on the model in what is app-owns-data in Power BI Embedded.)

Fabric IQ MCP needs the opposite: a real Entra work account, signed in, with access to the model. Your external viewer doesn't have one. To give them one you'd have to invite them as a guest, grant them access, and cover whatever licence Power BI requires for that content. That's the per-user wall that portals exist to avoid.

Whether B2B guest accounts work with Fabric IQ MCP isn't documented. We'd test it before promising it to anyone.

What about one shared account for everybody?

It's the obvious shortcut: let your backend sign in to Fabric IQ MCP as one account and relay answers to all your clients. Don't. RLS filters on the signed-in identity, so every client would query as that one account and see whatever it can see. That's exactly how client data leaks between clients. Microsoft's licensing terms also say that pooling users behind shared accounts (multiplexing) doesn't reduce the licences you need.

This isn't an oversight on Microsoft's side. Fabric IQ is designed to make governed data available to people in your organisation, under their own identity. That's the right design for internal use. It just isn't built for external viewers.

How does Fabric IQ MCP compare to the other AI options?

Fabric IQ MCP vs other Power BI AI options

Fabric IQ MCP Power BI Authoring MCP Fabric IQ in Copilot Chat Fabric Data Agents Embedded agentic AI (DataTako)
What it does Lets any MCP agent query reports and semantic models Builds and edits semantic models Answers questions in M365 Copilot Chat Configurable Q&A agent over Fabric data Natural-language Q&A for portal viewers
Status GA Not stated on overview page GA GA Live
Who signs in Delegated Entra work/school user Entra user (Fabric RBAC) M365 user with Copilot licence Entra user with Read on the source Portal viewer, mapped to an effective identity
Service principal Not supported Local setup only No Not documented Runs via the embedding layer
Capacity Not required to be Fabric or Premium Fabric workspace or Desktop Pro, PPU, Premium, Fabric. Not A or EM F2+ or P1+ Any Fabric F-SKU
Unlicensed external viewers No No No No Yes
Respects RLS Yes (RLS + OLS) N/A Yes (RLS + OLS) Yes (RLS + CLS) Yes, per sub-organisation
Based on Microsoft Learn documentation checked 30 September 2026 (Fabric IQ MCP, Power BI MCP servers overview, Fabric IQ in Microsoft 365 Copilot Chat, Fabric data agents). Requirements change often; verify before you build. Source: DataTako.

Is there an MCP server that works for external viewers?

Not from Microsoft. So we're building one: the DataTako MCP server is coming soon. It gives your clients' own AI tools, like Claude or Copilot, read-only access to the semantic models they can already see in their DataTako portal, under their own row-level security. They sign in with their portal account, not with an Entra account in your tenant.

The toolset follows the same pattern as Fabric IQ MCP: list the semantic models a user can access, read a model overview and its columns, run DAX, and look back at earlier queries. The difference is who can use it. Fabric IQ MCP serves people in your tenant. The DataTako MCP server serves the people outside it.

What does this mean if you deliver reporting to clients?

Split it into two audiences.

Your own team. Use Fabric IQ MCP. It's GA, it respects RLS, it doesn't need premium capacity for the model, and it works with the AI tools your analysts already use. For internal questions it's a better answer than building yet another report.

Your clients. Fabric IQ MCP won't reach them, and neither will Copilot or Fabric Data Agents. All three run as a signed-in user in your tenant. For external viewers the AI has to live where the viewer already is: in the portal, running through the same embedding layer that already filters their data with RLS. That's how DataTako's agentic AI works. Viewers sign in to the portal, ask a question in plain language, and the answer is scoped to their own sub-organisation, without a Microsoft licence per viewer. Once the DataTako MCP server is live, they'll be able to ask the same questions from their own AI tools too. (Background on the category: what is agentic AI for analytics.)

One practical point either way: MCP makes model quality visible. An agent writing DAX against your model relies on clear table names, measures that mean what they say and descriptions. If your model confuses people, it'll confuse the agent too.

Frequently asked questions

What is Fabric IQ MCP?

Fabric IQ MCP is Microsoft's remote Model Context Protocol server for Power BI. It lets MCP-compatible AI agents search Power BI reports and semantic models, read their schemas and run DAX queries. It's read-only, generally available, and applies the caller's existing permissions, including row-level and object-level security.

Does Fabric IQ MCP support service principal authentication?

No. Fabric IQ MCP only supports delegated OAuth 2.0 through Microsoft Entra ID with a work or school account. Microsoft's documentation states that service principal and application-only authentication aren't supported, so every request runs as a signed-in user.

Can external clients use Fabric IQ MCP on my Power BI reports?

Not through a normal client portal. Client portals use app-owns-data embedding with a service principal, and viewers don't have an Entra account in your tenant. Fabric IQ MCP requires a signed-in Entra work account with access to the model. Whether B2B guest accounts work isn't documented.

Does Fabric IQ MCP respect row-level security?

Yes. Power BI row-level security and object-level security keep restricting what comes back, based on the signed-in user. Microsoft notes that different users can get different results for the same query. That's also why you shouldn't route multiple clients through one shared account.

Do I need Fabric or Premium capacity to use Fabric IQ MCP?

No. Microsoft's documentation says reports and semantic models don't need to be hosted on Fabric or Premium capacity. The tenant's home region must support all Fabric workloads, and the user still needs access to the content under normal Power BI rules.

Is there an MCP server for external Power BI viewers?

Microsoft doesn't offer one: Fabric IQ MCP requires a signed-in Entra work or school account in your tenant. DataTako is launching an MCP server for portal viewers soon. It gives their own AI tools read-only access to the semantic models they can see in the portal, under their own row-level security, with their portal account.

What's the difference between Fabric IQ MCP and the Power BI Authoring MCP server?

Fabric IQ MCP is for consumption: answering business questions over existing reports and semantic models, read-only. The Power BI Authoring MCP server is for building models: creating and changing tables, measures, relationships and security roles. Microsoft advises against using the Authoring server to answer end users' questions.

‍

Blog Author Image
Bart van den Berg

Head of product

LinkedIn Icon Dark