Power BI MCP Server: What an AI Assistant Can Do With Your Models

Microsoft now documents three MCP servers for Power BI: one that edits semantic models, hosted or local, and two that query them. What each can do, how it signs in, its status, how to add it to VS Code, Claude or ChatGPT, and what never to let it change.

8 min read

A Power BI MCP server lets an AI assistant work with your semantic models through tools, not screenshots. Microsoft documents two jobs. The Power BI Authoring MCP server creates and changes models: tables, columns, measures, relationships, calculation groups, translations and security roles. It is in preview and comes hosted by Microsoft or as a local server on your machine. For answering questions, Microsoft now points to Fabric IQ, a read-only server that finds reports and models and runs DAX against them, and which is generally available. An older query endpoint, now called the Power BI Consumption MCP server, is still in preview for existing integrations. Every one of them acts as the person who signed in, with that person’s Power BI permissions.

The names have moved. What many guides call the “modeling” server is documented today as the Authoring server, although its npm package and repository still carry the name powerbi-modeling-mcp. What they call the “remote” server is the Consumption endpoint, and Microsoft’s overview of the Power BI MCP servers (opens in a new tab) says to use Fabric IQ for consumption instead. This guide follows Microsoft’s pages as they read at the end of September 2026. If MCP itself is new, start with what MCP is.

The servers side by side

  • Power BI Authoring MCP server, hosted: https://api.fabric.microsoft.com/v1/mcp/powerbi/authoring. Edits semantic models in Fabric workspaces. Signs in with Microsoft Entra ID as you. Preview. Needs a tenant setting, below.
  • Power BI Authoring MCP server, local: runs on your machine over stdio, from a VS Code extension, the @microsoft/powerbi-modeling-mcp npm package or a standalone executable. Adds Power BI Desktop, Power BI Project (PBIP) and TMDL files on disk, service principal sign-in, transactions and Analysis Services traces. Not supported on macOS.
  • Fabric IQ: https://fabriciq.svc.cloud.microsoft/v1/mcp/fabriciq. Read-only. Finds reports and semantic models by name, reads their metadata, searches for stored values and runs DAX. Generally available, delegated sign-in only.
  • Power BI Consumption MCP server: https://api.fabric.microsoft.com/v1/mcp/powerbi. The earlier query endpoint, with tools to run a query, read a model’s schema, read report metadata and generate DAX. Preview, kept for existing integrations.

Pick by the job, not by the word “remote”. Building or documenting a model is authoring. Asking what sales did last quarter is Fabric IQ. Microsoft is explicit that the Authoring server can run DAX so you can check what you are building, but it is not designed to answer business questions for end users.

What the Authoring server can do

According to Microsoft’s Authoring server documentation (opens in a new tab), an assistant can create, update and delete tables, columns, measures, relationships, hierarchies, calculation groups, perspectives, partitions and security roles; make bulk changes such as renames and translations across hundreds of objects; check a model against modelling best practices and apply the fixes; and run DAX queries to test measures while you build. It performs modelling operations only: it cannot change report pages or diagram layouts, and its DAX tools stop at 100,000 rows.

The permission on the model decides how much of that you get. With Write permission the assistant can change model objects. With only Build permission it can run DAX and nothing more. For the local server against a Fabric workspace, the capacity’s XMLA endpoint must also be set to Read Write.

Sign-in and the tenant setting

  • The hosted Authoring and Consumption servers need a Fabric administrator to turn on the tenant setting “Users can use the Power BI Model Context Protocol server endpoint (preview)”. If sign-in fails, check this first.
  • The hosted servers use Microsoft Entra ID OAuth as the signed-in user. The first tool call prompts you to sign in.
  • The local server signs in interactively through the Azure Identity SDK, or as a service principal from environment variables, which suits a CI pipeline.
  • No tenant setting blocks the local server. It connects through the XMLA endpoint, so the only way to block it is to disable XMLA, which blocks every other tool that uses it too.
  • Fabric IQ’s documentation (opens in a new tab) asks for the delegated Item.Read.All, Item.Execute.All and Dataset.Read.All permissions and does not support service principals or app-only sign-in.

Adding it to VS Code, Claude or ChatGPT

In VS Code with GitHub Copilot, add the server to your MCP configuration, such as .vscode/mcp.json. VS Code has its own registered Entra app, so there is nothing else to set up. Use the Local agent session: VS Code’s documentation says Copilot sessions can currently reach only local MCP servers that need no authentication, so the hosted server will not show up there. This registers the hosted Authoring server:

.vscode/mcp.json: hosted Authoring server
{
  "servers": {
    "powerbi-authoring-remote": {
      "type": "http",
      "url": "https://api.fabric.microsoft.com/v1/mcp/powerbi/authoring"
    }
  }
}

For the local server, start with it unable to write. The powerbi-modeling-mcp repository (opens in a new tab) lists a --readonly option that disables all write operations; the default, --readwrite, allows writes with confirmation. Remove the flag only when you are ready for changes.

.vscode/mcp.json: local Authoring server, read-only
{
  "servers": {
    "powerbi-authoring-local": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@microsoft/powerbi-modeling-mcp@latest", "--start", "--readonly"]
    }
  }
}

Claude Desktop and ChatGPT need one more step, because they expect to register themselves with the sign-in provider and Microsoft Entra ID does not support that. Microsoft’s guide for external MCP clients (opens in a new tab) has you create a single-tenant Entra app registration, add the client’s redirect URI, grant delegated Power BI permissions (SemanticModel.ReadWrite.All and Workspace.Read.All for authoring), and give the app’s client ID to the client:

  • Claude Desktop: Settings, Connectors, Add custom connector, with the server URL and the client ID as the OAuth Client ID. The Claude integration page shows the same connector flow for a board.
  • ChatGPT: a developer-mode app with OAuth and a user-defined OAuth client. Microsoft’s page still says Settings, Apps, Create App; OpenAI’s current menus put it under Plugins once developer mode is on, as Trello MCP with ChatGPT walks through.
  • GitHub Copilot CLI: has its own registered app, and Microsoft uses it for the Fabric IQ walkthrough, adding the server to ~/.copilot/mcp-config.json and running /mcp show FabricIQ to sign in.
  • Claude Code is not covered by Microsoft. The local server is the easy route there: claude mcp add --transport stdio powerbi -- npx -y @microsoft/powerbi-modeling-mcp@latest --start --readonly.

Register the hosted or the local Authoring server, not both. Microsoft warns that two overlapping tool sets make the assistant’s choice of tool ambiguous and cost extra tokens on every request.

Permissions: it is you

None of these servers has an identity of its own when you sign in interactively. Every call runs with your Fabric workspace role and your permissions on the model, so an assistant can change whatever you could change, in every workspace you can reach. When you query through Fabric IQ or the Consumption server as yourself, row-level security still filters what comes back. Microsoft adds two cautions. A service principal on the Consumption server is not subject to row-level security, so it sees everything the principal can. And the model’s metadata, schemas and query results travel to the MCP client and on to its language model provider, so your AI data-handling policy applies, not only Power BI’s security.

Safe prompts

Connect first, then read, then change one thing at a time and ask to see the plan before it runs. Microsoft’s own advice is to confirm the connection with a read-only question before asking for a change.

  • “Connect to semantic model ‘Sales’ in Fabric workspace ‘Finance Dev’ and list its tables and measures. Change nothing.”
  • “Find measures with no description. Propose descriptions in plain business terms and show them to me before writing any.”
  • “Check this model against modelling best practices and list the findings by severity. Do not apply fixes.”
  • “Write a DAX query for total sales by region for the last full quarter, run it, and show me the query with the result.”
  • “Apply only fix 2 from your list, then run a DAX query that proves the measure still returns the same totals.”

What never to let it change

  • Security roles and their filters on a production model. A wrong row-level security rule leaks data silently; draft it on a copy and have a person review it.
  • Anything on a production model without a backup. Microsoft says to back up first and, better, to work on PBIP files in Git so every change is a diff you can revert.
  • Deletions of tables, columns, relationships or partitions that reports depend on. Ask for a list of what would break first.
  • A shared model through a service principal that end users can reach, since row-level security does not apply to it on the Consumption server.
  • Anything through a sign-in with more rights than the job needs. Use an account with Build permission for questions and Write only on the model being worked on.

The same shape as for any database: a narrow login, a copy rather than the live system, and no production writes through a chat. Database MCP servers sets out those controls for Postgres and MySQL.

Keeping track of what the assistant found

A best-practice review of a large model produces a list, and a list in a chat window is gone next week. fenbs has no Power BI integration, but the same assistant can connect to a fenbs board over MCP at https://fenbs.ai/api/mcp and file each finding as a task: a bug for a measure that returns the wrong total, an enhancement for missing descriptions, with a priority from 1 to 10. They sit in To Do, Next Up, In Progress and Completed, each task holds a plan and a test status with notes, and every change is recorded under the assistant’s name. The steps are in the MCP docs.

Related

Claude across your Microsoft tenant: Claude and Microsoft 365. The same controls for SQL: database MCP servers. Before connecting anything that writes: MCP security risks.

Questions people ask.

Is there an official Power BI MCP server?

Yes. Microsoft documents the Power BI Authoring MCP server for creating and changing semantic models, in preview, and Fabric IQ, generally available, for read-only questions over reports and models. An earlier Power BI Consumption MCP server remains in preview for existing integrations.

What happened to the Power BI Modeling MCP server?

Microsoft now documents it as the Power BI Authoring MCP server, available hosted or local. The local package and its repository are still named powerbi-modeling-mcp.

Can the Power BI MCP server change my model without asking?

The Authoring server can create, update and delete model objects if you have Write permission. Start the local server with the readonly option, keep your client’s approval prompts on, back up the model and work on PBIP files under Git so changes can be reviewed and reverted.

Does the Power BI MCP server respect row-level security?

For queries, yes, when you sign in as yourself: Fabric IQ and the Consumption server run with your permissions, and row-level security still filters the results. Microsoft notes that queries through a service principal on the Consumption server are not filtered by row-level security.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.