> For the complete documentation index, see [llms.txt](https://docs.powermonitor.com.br/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.powermonitor.com.br/en/technical-documentation/instalacao/pre-requisitos.md).

# Prerequisites

Accounts, Entra ID permissions, Fabric tenant settings, and licensing required to install and operate Power Monitor.

Before installing Power Monitor, check the requirements below. The step-by-step guide is in [How do I install Power Monitor?](/en/readme/como-instalar-o-power-monitor.md)

## Required accounts

| Role                                                                                                                     | Purpose                                                                                                        | Required?                                 |
| ------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------- | ----------------------------------------- |
| Entra ID **Global Administrator** (or equivalent roles to register applications, create groups, and grant admin consent) | Automatic installation: create the App Registration, the Service Principal, the secret, and the security group | In the automatic installation             |
| **Fabric (Power BI) Administrator**                                                                                      | Enable the Fabric tenant settings for the Power Monitor application                                            | Always (can be a different person)        |
| **Gateway administrator**                                                                                                | Grant the application administrator access to the gateways, to monitor them                                    | To monitor gateways                       |
| **Owner** (or Contributor + User Access Administrator) on the Azure subscriptions                                        | Permissions to pause/scale capacities and read costs                                                           | For Capacity Governance and Capacity Cost |

{% hint style="warning" %}
An account without administrative roles can use Power Monitor after it is installed, but cannot complete the installation or grant the permissions.
{% endhint %}

## No infrastructure requirements

Power Monitor is **100% SaaS**:

* ❌ Does not require a dedicated server
* ❌ Does not require installing local agents or software
* ❌ Does not require opening firewall ports or a VPN
* ❌ Does not require a direct connection to your internal network

All communication with your tenant is done by the Power Monitor platform, in the cloud, with the Microsoft APIs. Users only need to access `app.powermonitor.com.br` and the Microsoft sign-in through the browser, with **pop-ups allowed** for Power Monitor.

## The Power Monitor application in your tenant

Power Monitor accesses your environment through an **application (Service Principal) registered in your Entra ID**, a member of a **security group**:

| Item                         | Automatic installation                                              | Manual installation                   |
| ---------------------------- | ------------------------------------------------------------------- | ------------------------------------- |
| App Registration             | Created as **PowerMonitor-APP**                                     | Created by you                        |
| Client secret                | Generated by the wizard                                             | Generated by you                      |
| Security group               | Created as **PowerMonitor-Group**, with the application as a member | Created by you (recommended)          |
| Graph application permission | **Directory.Read.All** granted to the application                   | Optional (see Additional Permissions) |
| Fabric tenant settings       | Applied by the wizard (if the account is a Fabric administrator)    | Enabled by you                        |

{% hint style="info" %}
In the manual installation, do **not** add Power BI Service permissions that require admin consent to the application: Microsoft does not allow Service Principals with this type of permission to use the read-only admin APIs.
{% endhint %}

## Fabric tenant settings

In **Fabric Admin portal › Tenant settings**, enabled **for the application's security group**:

**Required** (without them, collection does not work):

| Setting (technical name)                 | Name in the portal                                           | Purpose                                                |
| ---------------------------------------- | ------------------------------------------------------------ | ------------------------------------------------------ |
| `AllowServicePrincipalsUseReadAdminAPIs` | Service principals can access read-only admin APIs           | Inventory through the Scanner API and other admin APIs |
| `AdminApisIncludeDetailedMetadata`       | Enhance admin APIs responses with detailed metadata          | Model tables, columns, and measures                    |
| `AdminApisIncludeExpressions`            | Enhance admin APIs responses with DAX and mashup expressions | DAX and Power Query expressions (lineage, quality)     |
| `ServicePrincipalAccessGlobalAPIs`       | Service principals can call Fabric public APIs               | Fabric and Power BI REST APIs                          |

**Optional** (enable specific features):

| Setting (technical name)                     | Purpose                                                      |
| -------------------------------------------- | ------------------------------------------------------------ |
| `AllowServicePrincipalsUseWriteAdminAPIs`    | Update admin APIs, used in administrative actions            |
| `ServicePrincipalAccessPermissionAPIs`       | Actions that grant permissions through the Service Principal |
| `AllowServicePrincipalsCreateAndUseProfiles` | Service Principal profiles (embed scenarios)                 |
| `Embedding`                                  | Embedding content in applications                            |
| `OnPremAnalyzeInExcel`                       | Working with semantic models in Excel with a live connection |
| `DatasetExecuteQueries`                      | Query execution API on semantic models (DAX queries)         |

{% hint style="info" %}
Changes to tenant settings may take a few minutes to take effect. In **Settings › Additional Permissions › Basic Fabric permissions**, you can check and reapply these settings at any time.
{% endhint %}

## Consents requested during the automatic installation

In the **Required Permissions** step, the administrator grants (delegated) admin consent so that the wizard can configure the tenant:

| API                  | Delegated permissions                                                                                                                  | Use                                                                                                             |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- |
| **Microsoft Graph**  | `Application.ReadWrite.All`, `Directory.ReadWrite.All`, `Group.ReadWrite.All`, `Directory.Read.All`, `AppRoleAssignment.ReadWrite.All` | Create the application, the Service Principal, the secret, and the group, and assign the application permission |
| **Power BI Service** | `Tenant.ReadWrite.All`                                                                                                                 | Apply the tenant settings and list the workspaces                                                               |

These temporary permissions are **revoked automatically** at the end of the installation.

## Additional permissions (optional)

Granted later, in **Settings › Additional Permissions** (or in the wizard step of the same name):

| Permission                                                                           | Type                   | Enables                                                                                            |
| ------------------------------------------------------------------------------------ | ---------------------- | -------------------------------------------------------------------------------------------------- |
| **Application.Read.All** (Graph, application)                                        | Application permission | Client secret expiration notice                                                                    |
| **User.Read.All**, **Group.Read.All**, **GroupMember.Read.All** (Graph, application) | Application permission | Import users from Entra ID; group expansion on the permission screens                              |
| **Gateway administrator** and **connection user**                                    | Access in Power BI     | Gateway monitoring and connection mapping                                                          |
| **Workspace administrator**                                                          | Access in Power BI     | Features that require access to the workspace (for example, the Fabric Capacity Metrics workspace) |
| **Microsoft Teams bot**                                                              | Teams consent          | Alerts in Teams channels                                                                           |
| **Capacity Administrator and Contributor**, **Reader** on the subscriptions          | Azure                  | Pause, resume, and scale capacities                                                                |
| **Cost Management Reader** on the subscriptions                                      | Azure                  | Capacity cost                                                                                      |

## Capacity metrics source

To monitor capacity consumption, the **Microsoft Fabric Capacity Metrics** app must be installed in the tenant (through Power BI AppSource), in a current version, and the Power Monitor application must be an **Administrator** of its workspace. The automatic installation performs this configuration in the **Metrics Source** step; afterwards, in **Settings › Monitoring**. The app can be in a **Pro workspace**, as Microsoft recommends: there, Power Monitor's queries on it consume no capacity.

## Power BI / Fabric licensing

| Environment                               | What works                                                                                                                                                     |
| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Fabric (F-SKU)** capacities             | All features                                                                                                                                                   |
| **Power BI Premium per capacity (P-SKU)** | All Power BI features; pause/scale does not apply (it is not an Azure resource)                                                                                |
| **Power BI Embedded (A-SKU)**             | Power BI features and governance (pause/scale) through Azure                                                                                                   |
| **No dedicated capacity** (Pro/PPU only)  | Inventory, governance, permissions, audit, and gateways. Refresh failure monitoring covers only models on capacity, and Fabric items require a Fabric capacity |

## Related pages

* [Installation step by step](/en/technical-documentation/instalacao/passo-a-passo.md)
* [Automatic Installation](/en/readme/como-instalar-o-power-monitor/instalacao-automatica.md)
* [Manual Installation](/en/readme/como-instalar-o-power-monitor/instalacao-manual.md)
* [Azure permission configuration](/en/readme/como-instalar-o-power-monitor/configuracao-de-permissoes-no-azure-para-o-power-monitor.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.powermonitor.com.br/en/technical-documentation/instalacao/pre-requisitos.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
