Power BI Workspace Roles: Manage Permissions Without Content Access
You need to grant a user the ability to manage permissions on a Power BI workspace but not to view or edit the content. What minimum role should you assign?
Quick Answer
Admin is the answer, but it's worth understanding why it's the answer despite not being a clean fit: Power BI's workspace roles don't actually include one that grants permission management without also granting content access, so Admin ends up being the minimum role that satisfies the requirement simply because it's the only role with permission-management rights at all. Admin sits at the top of the role hierarchy and includes managing workspace membership and permissions alongside full content access, and there's no narrower role positioned specifically for permissions alone. The other roles fail for the same underlying reason, each in a different direction: Contributor can view and edit content but has no ability to manage who else has access; Viewer is limited to read-only content access; and Member allows viewing and editing but likewise stops short of managing permissions. None of them include the specific capability the scenario asks for, which leaves Admin as the only option that actually contains it, even though it grants more than strictly necessary. This is a useful pattern to recognize on scenario questions generally: when a requirement doesn't map cleanly onto any role's intended purpose, look for the minimum role that happens to include the needed capability as a side effect, rather than assuming a perfectly scoped role must exist.
⚠ Common exam trap
Note that the Admin role still allows viewing and editing content; it is not a permissions-only role. The minimum role to manage permissions is Admin, but it comes with full content access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Admin
The Admin role is the only workspace role that can manage permissions and membership, even though it also allows viewing and editing content. The minimum role required to manage permissions is Admin. Option A is incorrect because Contributor can view and edit content but cannot manage permissions. Option B is incorrect because Viewer can only view content and cannot manage permissions. Option C is incorrect because Member can view and edit content but cannot manage permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contributor
Why it's wrong here
Contributor grants permission to create and edit content such as reports and datasets, so it fails the requirement to withhold view and edit rights. It is tempting because Contributor does not manage workspace permissions at all. Admin is the minimum role that manages permissions while excluding content access.
- ✗
Viewer
Why it's wrong here
Viewer grants read-only access to workspace content and cannot manage permissions, so it fails both parts of the requirement. It is tempting because Viewer is the least-privileged role and seems minimal. Admin is the minimum role that can manage permissions without granting content editing.
- ✗
Member
Why it's wrong here
The Member role grants permission to view and edit workspace content as well as manage access, so it exceeds the requirement to manage permissions without viewing or editing content. It is tempting because Member does include permission management. The Admin role grants permission management without content access, which is what the scenario requires.
- ✓
Admin
Why this is correct
Admin can manage permissions, but it also allows viewing and editing content; there is no role that manages permissions without content access.
Go deeper
Related to this question
About these practice questions
This PL-300 question is part of Courseiva's 524-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PL-300
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to grant a user the ability to manage permissions, add members, and edit content in a Power BI workspace, but not delete the workspace. Which role should you assign?
easy- ✓ A.Member
- B.Admin
- C.Contributor
- D.Viewer
Why A: The Member role is correct because in a Power BI workspace it grants the ability to add members, manage permissions, and edit and publish content, while it does not allow deleting or renaming the workspace, which matches the stated requirement. Admin would be too permissive since it can delete the workspace and manage all aspects of it. Contributor allows editing and publishing content but cannot add members or manage permissions. Viewer only provides read access to content and cannot edit or manage anything.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-300 exam.