Microsoft’s own directory lists 13 Fabric MCP servers (Microsoft Learn, 2026), before counting the separately documented Fabric IQ MCP, each with its own release status, sign-in model, and audit coverage. According to Microsoft’s FabCon and SQLCon 2026 announcement (Azure blog, 2026), the local Fabric MCP server is generally available and the remote Core server is in public preview. Skills for Fabric teach your coding agent what to do; the servers do it.
No single Microsoft doc asks what all of them, switched on together, let one agent reach. The answer depends on which servers your team connected, under which identity, and with which client approval settings. A “Fabric MCP” readiness call is really several calls, one per server. Permissions are the predictable part, since every live call uses the signed-in identity’s existing Fabric roles. Audit coverage doesn’t: Fabric records supported Core operations, and other paths depend on the underlying service.
| Field | What Microsoft’s documentation says (September 28, 2026) |
|---|---|
| Server families | Core, local, Fabric IQ MCP, Ontology MCP, Real-Time Intelligence, plus workload servers (Microsoft Learn) |
| Sign-in | Entra ID OAuth for remote servers; Azure CLI identity or service principal for local live operations |
| Audit coverage | Supported Core operations recorded; the local server emits no Fabric audit logs itself (Microsoft Learn) |
| Skills for Fabric clients | GitHub Copilot, VS Code, Claude Code, Cursor, Windsurf, Codex, Jules, OpenCode (Microsoft Learn) |
What is a Fabric MCP server, and how is it different from Skills for Fabric?
A Fabric MCP server is a running service that turns Fabric operations into tools an AI agent can call, while Skills for Fabric are the instructions that tell the agent which tools to call and how. Microsoft draws the line itself in its Skills for Fabric overview (Microsoft Learn, 2026): “Skills teach the AI assistant what to do. MCP servers do it.”
That is the split between agent skills vs MCP on one platform. Each skill is a SKILL.md file, the format behind agent skills generally.
- Skills: MIT-licensed in the microsoft/skills-for-fabric repository (GitHub, 2026), supported in GitHub Copilot CLI, VS Code, Claude Code, Cursor, Windsurf, and
AGENTS.mdtools. - MCP servers: separate processes that execute calls against your tenant, using the protocol in this MCP architecture deep dive.
The two often arrive together: per the Skills for Fabric MCP setup guide (GitHub, 2026), some bundles configure remote servers automatically. The server, not the skill, decides what the agent can touch, which is why MCP matters for AI agents as an access question and governed context for agent skills starts with the servers each skill wires up.
Skills instruct; each connected server adds its own reach into Fabric under one identity’s permissions.
How many MCP servers does Microsoft Fabric actually have, and what does each do?
Microsoft Fabric has at least 14 MCP servers: 13 in Microsoft’s server directory (Microsoft Learn, 2026) plus Fabric IQ MCP, described in the Fabric MCP Servers overview (Microsoft Learn, 2026). Five families cover most agent work.
Fabric Core MCP Server (remote, preview)
Core exposes supported Fabric REST operations as typed tools at https://api.fabric.microsoft.com/v1/mcp/core, signed in through Microsoft Entra ID. The Core quickstart (Microsoft Learn, 2026) says it “is currently in preview.” Of the two platform servers in Microsoft’s Core-versus-local comparison (Microsoft Learn, 2026), only Core handles workspace creation and deletion, workspace roles, and workspace folders.
Fabric MCP Server (local, generally available)
The local server is open source in the microsoft/mcp repository (GitHub, 2026), and Microsoft’s March 2026 announcement (Azure blog, 2026) called it “now generally available.” Per the local quickstart (Microsoft Learn, 2026), documentation tools need no sign-in, while live operations use an Azure CLI identity or a service principal. It adds OneLake file operations, and it can still create items.
Fabric IQ MCP (remote, read-only, generally available)
Fabric IQ MCP lets agents find Power BI reports and semantic models, inspect metadata, and run DAX. Its setup guide (Microsoft Learn, 2026) says it “is generally available,” with delegated sign-in only and row-level security still enforced. Results are only as current as the Power BI semantic model’s last refresh, the tension behind semantic layer for BI vs AI agents.
Ontology MCP Server (remote, preview)
In its March 2026 FabCon announcement (Azure blog, 2026), Microsoft said Fabric IQ ontologies would “soon become accessible through an MCP server in preview.” The Ontology MCP guide (Microsoft Learn, 2026) now documents it as preview, requiring F2 or higher capacity (or Power BI Premium P1+) and an ontology item.
The Real-Time Intelligence family
Per Microsoft’s RTI MCP overview (Microsoft Learn, 2026), Real-Time Intelligence has an open-source local server plus three hosted ones: Eventhouse for KQL, Activator for alert rules, and Operations agent for instructions and playbooks.
| Server | Hosting | Status (Sept 2026) | Sign-in | What an agent can do |
|---|---|---|---|---|
| Fabric Core MCP | Remote | Preview | Entra ID OAuth | Create, update, delete workspaces; manage roles, folders, items |
| Fabric MCP Server | Local | Generally available | Azure CLI or service principal | API docs offline, OneLake files, item operations |
| Fabric IQ MCP | Remote | Generally available | Entra ID, delegated only | Read Power BI metadata, run DAX, read-only |
| Ontology MCP | Remote, per item | Preview, F2+ capacity | Entra ID | Serve ontology entities and relationships |
| RTI family | Local plus 3 remote | Not stated on overview | Per server; actions follow Fabric RBAC | KQL queries, alert rules, operations playbooks |
The remaining directory entries cover single workloads such as Data Warehouse T-SQL and Data Factory. Fourteen entry points is the sprawl an MCP gateway consolidates, so MCP gateway vs single MCP server now applies inside one vendor. Each surface raises its own governance question before an agent built on it can be trusted.
What can an AI agent actually do through a Fabric MCP server?
Through Fabric’s MCP servers, an agent can create workspaces and lakehouses, change who has access, query Power BI models, and configure monitoring, all from a chat prompt, per Microsoft’s own examples.
The Core quickstart (Microsoft Learn, 2026) lists prompts that write as well as read:
- “Create a workspace called Sales Analytics Dev”
- “Create a lakehouse named CustomerData in the Dev workspace”
- “Add [email protected] as a Contributor to my Dev workspace”
Microsoft puts a warning directly above them: “Some examples create resources or change access permissions. Review the proposed tool calls and your client’s approval settings before allowing changes.”
The read side is just as broad. Through Fabric IQ MCP, the agent itself chains discovery, schema lookup, value search, and DAX execution to answer a business question, the pattern where MCP delivers business context to an agent. On the Real-Time Intelligence side, the Operations agent server generates playbooks and manages monitoring, so a single prompt can reconfigure what an operations agent monitors.
Who should run which prompt is a role question, the lens behind the FabCon Europe 2026 sessions by role. Every one of these actions runs with the signed-in identity’s permissions. Which identity that is, and what it can reach, is the question a governed context layer has to answer for every connected surface, Fabric’s included.
Should you use Fabric’s local or remote MCP server?
Choose the local server for individual development that needs offline docs or local files, and remote servers for shared, always-on agent workflows. Microsoft’s clearest decision table, in the RTI MCP overview (Microsoft Learn, 2026), recommends local for full control and air-gapped access, and remote for automatic updates and cloud agent platforms such as Microsoft Copilot Studio or Microsoft Foundry. The same trade-offs apply to Core and the local server.
| Criterion | Local Fabric MCP server | Remote Core MCP server |
|---|---|---|
| Works offline | Yes, for documentation tools | No |
| Live operations sign-in | Azure CLI identity or service principal | Entra ID OAuth token |
| Maturity | Generally available | Preview |
| Fabric audit trail | Not emitted by the server itself | Supported operations recorded |
| Best for | One developer and one coding assistant | Team or organization-wide agent workflows |
The Fabric MCP Servers overview (Microsoft Learn, 2026) expects mixing: “You can use multiple servers simultaneously.” Formal MCP registry vs ad hoc usage then becomes the choice between knowing which servers each agent reaches and finding out later, often through a private MCP server registry. Hosting is the smaller choice; the record of what is connected, under whose identity, is what makes an agent trustworthy.
Does connecting a Fabric MCP server change what an agent is allowed to do?
Connecting a Fabric MCP server grants no new permissions, but the audit trail and destructive-action safeguards vary by server and by client. Microsoft’s Security and compliance guidance (Microsoft Learn, 2026) states both halves.
“Connecting an MCP server doesn’t itself grant additional Fabric permissions,” and live operations use the authenticated identity’s permissions, “which can differ from the person interacting with the MCP client.” That guidance is scoped to Core and the local server, and the Fabric IQ MCP guide (Microsoft Learn, 2026) makes the same promise for Power BI content. That makes AI agent identity the first thing to pin down, with role-based access control for context behind it.
On audit, the same page is precise:
- Fabric records supported Core operations under the identity that ran them.
- “The local MCP server doesn’t itself emit Fabric audit logs.”
- “Don’t assume that every MCP tool call appears in Fabric audit logs.”
Captured events land in the Microsoft Purview audit log, which per Track user activities in Microsoft Fabric (Microsoft Learn, 2026) needs the Audit Logs role and defaults to a seven-day search. Those gaps are why context observability for AI agents and decision traces sit beside platform logs.
The RTI guidance adds the client side: “Autonomous or misconfigured clients might perform destructive actions,” and safeguards “aren’t standardized in the MCP specification.” Compliance is the customer’s job, where an enterprise AI agent guardrails checklist, an AI agent access control model, and an AI-ready data checklist come in.
Ownership stays open: when an agent creates a lakehouse through Core, who reviews, promotes, or retires it? That is the question behind who governs a Fabric item an agent created, extending the Fabric AI agent governance questions to agent-authored artifacts. Microsoft has drawn the permission boundary; audit completeness and client safeguards remain your team’s decisions.
How Atlan approaches governed context for AI agents
Microsoft’s security section leaves your team a list: how broadly each identity is scoped, which of the 14 or more servers (Microsoft Learn, 2026) are live, and which calls leave a trace. Fabric’s RBAC decides what an agent may do inside Fabric. It doesn’t tell the agent what a table means, who owns it, or whether its definition is certified.
Atlan is the Context Layer for AI, built for that second question across platforms. Connectors for warehouses, BI tools including Power BI, dbt, and orchestrators bring definitions, lineage, and ownership into one Enterprise Data Graph. The Atlan MCP server delivers that context to any MCP-speaking agent; the Context Lakehouse keeps every historical state on Apache Iceberg, so a team can reconstruct what an agent knew.
In Context Engineering Studio, domain owners approve what becomes canonical before agents read it, context engineering applied to a shared repo. Per MCP gateway vs context layer, the gateway routes calls; the context layer decides what the agent knows. What makes data AI-ready sets the bar underneath, and the enterprise context layer is where the result lives.
Every Fabric MCP server you connect widens what one agent can reach
Fabric’s MCP surface is at least 14 servers deep (Microsoft Learn, 2026): local and Fabric IQ MCP generally available, Core and Ontology in preview. Permissions hold the line, since no server grants more than the signed-in identity already has.
Audit coverage and destructive-action safeguards don’t hold evenly, and Microsoft’s docs hand both to you. Before an agent goes live, write down which servers it can reach, under which identity, with which approval settings, and where its actions will show up. Those are also the questions to bring to the agent sessions in the FabCon Europe 2026 guide.
FAQs about Fabric MCP servers
1. What is the difference between Skills for Fabric and a Fabric MCP server?
Skills for Fabric are markdown instructions that teach an AI coding tool which Fabric APIs and query patterns to use. A Fabric MCP server is the running service that executes those calls against your tenant. In Microsoft’s words, skills teach the assistant what to do, and MCP servers do it.
2. What is the difference between Fabric Core MCP Server and Fabric MCP Server (local)?
Core is a Microsoft-hosted endpoint for managing workspaces, items, folders, and roles, signed in through Microsoft Entra ID. The local server is open source, runs on your machine, and adds offline API docs and OneLake file operations. Core is in preview; the local server is generally available.
3. Is Fabric’s remote Core MCP server generally available yet?
No. As of September 2026, Microsoft Learn marks Fabric Core MCP Server as preview, with features that may change before general availability. The local server and Fabric IQ MCP are generally available, so check status per server, not for Fabric as a whole.
4. Does connecting an MCP server give an agent more permissions than the signed-in user already has?
No. Microsoft states that connecting an MCP server doesn’t itself grant additional Fabric permissions. Live operations run with the authenticated identity’s existing roles, which can differ from the person typing prompts, for example when a service principal is configured.
5. Are actions taken through a Fabric MCP server always recorded in Fabric’s audit log?
Not always. Fabric records supported Core operations under the identity that ran them, but the local server doesn’t itself emit Fabric audit logs, and Microsoft says not to assume every MCP tool call appears there. Captured events are searchable in the Microsoft Purview audit log.
6. Which AI coding tools work with Fabric’s MCP servers?
Microsoft’s setup guides use GitHub Copilot in VS Code and GitHub Copilot CLI, and any MCP host that supports the server’s transport and sign-in flow can connect. Skills for Fabric also support Claude Code, Cursor, Windsurf, Codex, Jules, and OpenCode.