Tableau Server and Online
Tableau Server and Online Interview with follow-up questions
1. Can you explain the main differences between Tableau Server and Tableau Online?
Note: "Tableau Online" was renamed to Tableau Cloud in 2022. You may still see "Tableau Online" in older study materials and some exam questions, but the current name is Tableau Cloud.
Tableau Server is a self-hosted platform. The organization installs and maintains it on its own infrastructure — either on-premises hardware or a customer-managed cloud environment (AWS, Azure, GCP). This gives full control over configuration, network isolation, upgrade timing, hardware sizing, and compliance with specific regulatory requirements. It requires dedicated IT resources to administer and patch.
Tableau Cloud is a fully managed SaaS offering. Salesforce/Tableau handles infrastructure provisioning, upgrades, patching, and scaling. Organizations access it via a subdomain on Tableau's hosted environment (e.g., us-east-1.online.tableau.com). There is no server to install or maintain.
| Tableau Server | Tableau Cloud | |
|---|---|---|
| Hosting | Customer-managed | Tableau-managed (SaaS) |
| Infrastructure | On-prem or customer cloud | Tableau's cloud |
| Maintenance | Customer IT team | Handled by Tableau |
| Customization | High (SAML, LDAP, custom SSO, etc.) | More limited |
| On-prem data access | Direct | Requires Tableau Bridge agent |
| Data residency control | Full | Depends on Tableau's regions |
| Cost model | License + infrastructure | Subscription per user |
Key difference for on-premises data: Tableau Cloud cannot reach data behind a corporate firewall directly. Organizations use Tableau Bridge — a lightweight agent installed in the private network — to proxy extract refreshes and some live connections from Tableau Cloud to on-premises data sources.
Follow-up 1
What are the advantages of using Tableau Server over Tableau Online?
There are several advantages of using Tableau Server over Tableau Online:
Control and customization: Tableau Server allows organizations to have full control over their data and infrastructure. They can customize the server to meet their specific needs and integrate it with other systems and data sources.
Security and compliance: With Tableau Server, organizations can ensure compliance with security and governance policies. They have full control over data access and can implement security measures such as encryption and authentication.
Performance and scalability: Tableau Server can be optimized for performance and can handle large amounts of data and concurrent users. Organizations can scale their server infrastructure as needed to meet growing demands.
Cost savings: While Tableau Server requires upfront investment in hardware and software licenses, it can be more cost-effective in the long run for organizations with large user bases or complex data requirements.
Follow-up 2
Can you give an example of a scenario where Tableau Online would be more beneficial than Tableau Server?
Tableau Online can be more beneficial than Tableau Server in scenarios where:
Quick deployment: Tableau Online is a fully hosted platform, so organizations can get started quickly without the need to set up and manage their own server infrastructure.
Limited resources: Organizations that don't have the resources or expertise to manage their own server can benefit from Tableau Online. It eliminates the need for hardware and software maintenance and allows organizations to focus on their core business.
Collaboration with external stakeholders: Tableau Online provides an easy way to share dashboards and reports with external stakeholders such as clients, partners, or vendors. It allows for real-time collaboration and data sharing without the need for VPN or firewall configurations.
Temporary projects: Tableau Online can be a cost-effective solution for temporary projects or short-term data analysis needs. Organizations can subscribe to Tableau Online for the duration of the project and then cancel the subscription when it is no longer needed.
Follow-up 3
How does data security differ between Tableau Server and Tableau Online?
Data security differs between Tableau Server and Tableau Online in the following ways:
Hosting: Tableau Server is self-hosted, which means organizations have full control over their data and can implement their own security measures. Tableau Online, on the other hand, is hosted by Tableau and follows industry-standard security practices.
Authentication: Both Tableau Server and Tableau Online support various authentication methods, such as Active Directory, SAML, and OAuth. However, with Tableau Server, organizations have more control over user authentication and can integrate it with their existing authentication systems.
Encryption: Tableau Server allows organizations to encrypt data at rest and in transit, providing an extra layer of security. Tableau Online also encrypts data in transit and at rest, but the encryption keys are managed by Tableau.
Compliance: Tableau Server gives organizations more control over compliance with security and governance policies. They can implement their own policies and ensure data compliance. Tableau Online follows industry-standard compliance practices and undergoes regular security audits.
Follow-up 4
What are the system requirements for Tableau Server?
The system requirements for Tableau Server depend on factors such as the number of users, the size of data, and the complexity of dashboards. Here are some general guidelines:
Hardware: Tableau Server requires a server-class machine with a minimum of 8 cores, 32 GB of RAM, and 50 GB of free disk space. The actual requirements may vary based on the workload.
Operating system: Tableau Server is compatible with Windows Server and Linux distributions such as Red Hat Enterprise Linux and CentOS.
Database: Tableau Server supports various databases for storing metadata and extracts, including PostgreSQL, Microsoft SQL Server, and Oracle.
Network: Tableau Server requires network connectivity for user access and data source connectivity. It is recommended to have a fast and reliable network connection.
It is important to consult the official Tableau Server documentation for detailed and up-to-date system requirements.
2. How would you publish a workbook from Tableau Desktop to Tableau Online?
Note: "Tableau Online" was renamed to Tableau Cloud in 2022. The steps below apply to publishing to Tableau Cloud.
To publish a workbook from Tableau Desktop to Tableau Cloud:
Sign in: In Tableau Desktop, go to Server > Sign In. Enter your Tableau Cloud site URL (typically in the format
https://prod-useast-a.online.tableau.com/#/site/yoursitename) and authenticate using your credentials, SAML SSO, or Google/Salesforce OAuth as configured by your admin.Open the Publish dialog: With the workbook open, go to Server > Publish Workbook.
Select the project: Choose the project (organizational folder) on your Tableau Cloud site where the workbook should be published. Projects define permission inheritance and content organization.
Name the workbook: Confirm or edit the name and optionally add tags.
Handle the data source: Decide whether to embed the data source in the workbook or publish it separately as a shared data source. For extracts, configure the refresh schedule. If the data is on-premises (behind a firewall), ensure Tableau Bridge is installed and configured — otherwise Tableau Cloud cannot reach the data for scheduled refreshes.
Set permissions: Configure who can view, interact with, or edit the published workbook.
Click Publish: Tableau uploads the workbook to Tableau Cloud. A browser window opens to the published content.
Gotcha: Tableau Cloud only supports scheduled extract refreshes for on-premises data when Tableau Bridge is running. Live connections to on-premises databases from Tableau Cloud also require Bridge for certain connector types. Cloud-hosted data sources (Snowflake, BigQuery, Amazon Redshift, etc.) connect directly without Bridge.
Follow-up 1
What are the steps to refresh data in Tableau Online?
To refresh data in Tableau Online, follow these steps:
- Open the workbook in Tableau Online.
- Click on the 'Data' menu and select 'Refresh All Extracts'.
- Tableau Online will start refreshing the data for all the data sources used in the workbook.
You can also schedule data refreshes in Tableau Online to automate the process.
Follow-up 2
Can you describe how to schedule data refreshes in Tableau Online?
To schedule data refreshes in Tableau Online, follow these steps:
- Open the workbook in Tableau Online.
- Click on the 'Data' menu and select 'Extract Refresh Schedules'.
- In the 'Extract Refresh Schedules' dialog box, click on the 'Add Refresh Schedule' button.
- Configure the schedule by selecting the frequency, start time, and other options.
- Click on the 'Save' button to create the data refresh schedule.
Tableau Online will automatically refresh the data based on the schedule you have set.
Follow-up 3
What happens if a data refresh fails in Tableau Online?
If a data refresh fails in Tableau Online, Tableau will send an email notification to the owner of the workbook and any other users who have subscribed to the workbook. The email will contain information about the failure and any error messages that were encountered.
You can also view the refresh history in Tableau Online to see the status of each data refresh and any error messages that were encountered.
3. What is the role of a Site Administrator in Tableau Server?
A Site Administrator in Tableau Server (or Tableau Cloud) has the highest level of permissions within a specific site. Their responsibilities include:
User and group management:
- Add, remove, and manage users on the site
- Assign and change site roles (Creator, Explorer, Viewer, and their variants) that determine what each user is licensed to do
- Create and manage groups to simplify permission assignment
Content governance:
- Create and manage projects (folders), including setting permissions and locking project permissions so content inherits from the project
- Control which content (workbooks, data sources, flows) is published to which projects
- Move, delete, or reassign ownership of content
Data and connection management:
- Manage published data sources and their refresh schedules
- Configure credentials and connection settings for data sources
- Set up and monitor extract refresh jobs
Security and access control:
- Define permission rules at the project, workbook, and data source level
- Implement and enforce data source permissions to restrict who can download or connect to underlying data
Site configuration (Server):
- Configure authentication settings (SAML, OAuth, MFA) at the site level
- Manage site storage quotas and content limits
- View and export site activity logs for auditing
Important distinction: A Site Administrator manages content and users within a site. A Server Administrator has access to the underlying Tableau Server installation itself (hardware, processes, server-wide configuration) and manages multiple sites. A Creator license is required to hold the Site Administrator role. On Tableau Cloud, the equivalent top-level role is Site Administrator Creator.
Follow-up 1
What are some typical tasks a Site Administrator would perform in Tableau Server?
Some typical tasks a Site Administrator would perform in Tableau Server include:
- Installing and configuring Tableau Server
- Managing user accounts and permissions
- Creating and managing sites and projects
- Monitoring server performance and troubleshooting issues
- Managing data sources and ensuring data integrity
- Implementing security measures and managing user access
- Upgrading Tableau Server to newer versions
- Collaborating with other administrators and stakeholders to optimize server usage and performance.
Follow-up 2
How does a Site Administrator manage user access in Tableau Server?
A Site Administrator manages user access in Tableau Server by assigning permissions and roles to users. They can create user accounts, assign them to specific groups, and define their level of access to various resources such as projects, workbooks, and data sources. The administrator can also set up authentication methods, such as Active Directory or SAML, to control user access. Additionally, the administrator can monitor and audit user activity to ensure compliance and security.
Follow-up 3
Can you explain how a Site Administrator would handle data sources in Tableau Server?
A Site Administrator handles data sources in Tableau Server by managing their availability, security, and performance. They can publish data sources to the server, making them accessible to users for analysis and reporting. The administrator can also set permissions on data sources to control who can view or edit them. They can monitor the usage and performance of data sources, optimize them for better performance, and troubleshoot any issues that may arise. Additionally, the administrator can schedule data source refreshes to ensure that the data is up-to-date for users.
4. Can you describe how to set up a project in Tableau Online?
Note: "Tableau Online" was renamed to Tableau Cloud in 2022. The steps below apply to Tableau Cloud.
Projects in Tableau Cloud are organizational containers (similar to folders) that group related workbooks and data sources together and define the permission structure for that content.
To set up a project in Tableau Cloud:
- Log in to your Tableau Cloud site in a browser and navigate to the Home or Explore page.
- Click "New" in the top-right area and select "Project", or go to Explore > New > Project.
- Name the project and optionally add a description to help users understand what content belongs in it.
- Set the permission mode: Choose whether permissions are Locked (all content inherits permissions from the project and cannot be changed at the individual content level — recommended for governance) or Customizable (content owners can set their own permissions at the workbook/data source level).
- Click "Create Project". The project now appears in the Explore view.
After creating the project:
- Assign users or groups permissions on the project (View, Publish, Project Leader, etc.) via the project's permissions menu.
- Create nested sub-projects inside the project for further organization.
- Publish workbooks and data sources into the project from Tableau Desktop (selecting the project in the Publish Workbook dialog) or by moving existing content into it from the Explore view.
Key interview point: Locking project permissions is a best practice for governance — it ensures that even if a workbook is published by a Creator, the access rules are set by the Site Administrator at the project level rather than by each individual author.
Follow-up 1
What are some best practices for organizing projects in Tableau Online?
Here are some best practices for organizing projects in Tableau Online:
- Use a consistent naming convention for projects to make it easier to find and manage them.
- Create separate projects for different teams or departments to keep the content organized.
- Use project-level permissions to control access to the content within each project.
- Consider creating sub-projects within a main project to further organize the content.
- Regularly review and clean up unused or outdated projects to keep the environment tidy.
Follow-up 2
How would you manage permissions for a project in Tableau Online?
To manage permissions for a project in Tableau Online, follow these steps:
- Go to the 'Projects' tab in Tableau Online.
- Click on the project for which you want to manage permissions.
- Click on the 'Permissions' tab.
- Use the checkboxes to grant or revoke permissions for specific users or groups.
- Click on the 'Save' button to apply the changes.
You can set permissions at the project level, workbook level, or view level, depending on your needs.
Follow-up 3
Can you explain how to move a workbook between projects in Tableau Online?
To move a workbook between projects in Tableau Online, follow these steps:
- Go to the 'Projects' tab in Tableau Online.
- Click on the project that currently contains the workbook.
- Locate the workbook and click on the ellipsis (...) button next to it.
- Select 'Move' from the dropdown menu.
- Choose the destination project where you want to move the workbook.
- Click on the 'Move' button to complete the process.
Note that moving a workbook to a different project may affect its permissions and access for other users.
5. How does Tableau Server handle data security?
Tableau Server provides a layered security model that controls both access to the platform and access to data within it.
Authentication (who can log in):
- Local authentication (Tableau-managed username and password)
- Active Directory / LDAP integration
- SAML 2.0 SSO for enterprise identity providers (Okta, Azure AD, etc.)
- OAuth for cloud sources (Google, Salesforce, Snowflake, etc.)
- Multi-Factor Authentication (MFA) — supported natively on Tableau Cloud and via identity provider on Tableau Server
Authorization (what users can do):
- Site roles: Creator, Explorer, Viewer (and their variants) define the maximum capability of a user across the site
- Project permissions: control who can publish to, view content in, or manage a project
- Workbook and data source permissions: fine-grained control at the individual content level (view, interact, download, edit, move, delete, etc.)
- Locking project permissions: enforces that all content in a project inherits the project-level permissions, preventing content owners from overriding access
Data-level security:
- Row-level security: implemented via user functions (USERNAME(), ISMEMBEROF()) in calculated fields or via entitlement tables joined to the data source, restricting which rows each user can see
- Column-level security / data policy filters: available on Tableau Cloud to restrict access to specific columns based on user attributes
- User filters: server-managed filters that automatically apply a filter based on the logged-in user
Data in transit and at rest:
- SSL/TLS encryption for all communication between clients and Tableau Server
- Encryption of extract files (.hyper) at rest on the server
- Support for customer-managed encryption keys on Tableau Cloud
Auditing:
- Tableau Server logs user sign-in events, content access, and administrative actions for compliance and audit purposes
Follow-up 1
What are the different levels of data security in Tableau Server?
Tableau Server provides multiple levels of data security, including:
Authentication: Tableau Server supports various authentication methods such as local authentication, Active Directory, SAML, and OAuth. This ensures that only authorized users can access the server.
Authorization: Tableau Server allows administrators to define permissions and access levels for users and groups. They can control who can access specific workbooks, views, and data sources, and what actions they can perform.
Encryption: Tableau Server encrypts data in transit using SSL/TLS protocols. It also supports encryption at rest for data stored in Tableau data extracts.
Data Source Security: Tableau Server allows administrators to control access to data sources. They can define permissions at the data source level, ensuring that only authorized users can connect to and use specific data sources.
Row-Level Security: Tableau Server provides row-level security, which allows administrators to restrict access to specific rows of data based on user roles or attributes.
User Filters: Tableau Server allows administrators to set up user filters, which dynamically limit the data that users can see based on their attributes or roles.
Follow-up 2
Can you explain how row-level security works in Tableau Server?
Row-level security in Tableau Server allows administrators to restrict access to specific rows of data based on user roles or attributes. Here's how it works:
Define Roles: Administrators define roles in Tableau Server and assign users to these roles.
Create Security Filters: For each data source, administrators can create security filters based on user roles or attributes. These filters define which rows of data each role can access.
Apply Security Filters: The security filters are applied to the data source, ensuring that users can only see the rows of data they are authorized to access.
Dynamic Filtering: When users interact with views or dashboards, Tableau Server dynamically applies the security filters to limit the data they can see.
By using row-level security, administrators can ensure that each user only sees the data that is relevant to them, while maintaining data confidentiality and integrity.
Follow-up 3
How would you set up user filters in Tableau Server?
To set up user filters in Tableau Server, follow these steps:
Define User Attributes: Identify the user attributes that you want to use for filtering, such as department, region, or role.
Create User Filters: In Tableau Server, go to the data source tab and select the data source you want to apply user filters to. Click on the 'User Filters' option.
Define User Filter Rules: For each user attribute, define the filter rules that determine which data each user can access. For example, you can create a rule that allows users with the 'Sales' role to only see data for their assigned region.
Apply User Filters: Once the user filters are defined, apply them to the data source. Tableau Server will dynamically apply the filters when users interact with views or dashboards, limiting the data they can see.
By setting up user filters, you can ensure that each user only sees the data that is relevant to them, based on their attributes or roles.
6. What is the difference between Creator, Explorer, and Viewer roles in Tableau Cloud/Server?
Tableau uses a role-based licensing model that determines what actions each user can perform.
| Role | License | Capabilities |
|---|---|---|
| Creator | Full license | Can connect to new data sources, build workbooks in Desktop or web authoring, publish content, administer sites |
| Explorer | Mid-tier | Can interact with published content, use web authoring to edit existing workbooks (limited), create basic views from published data sources; cannot connect to raw data sources |
| Viewer | Entry-level | Can view and interact with published dashboards and stories; can subscribe and download data; cannot create or edit content |
Key interview points:
- Site Administrators require a Creator license.
- Tableau Prep flows can only be published and run by Creators.
- Tableau Pulse metrics subscriptions are available to all roles including Viewers.
- Role assignment is done per site; a user can have different roles on different sites within the same Tableau Server/Cloud instance.
Live mock interview
Mock interview: Tableau Server and Online
- Read your scene and goals
- Talk it out; goals tick off live
- Get a score and stronger lines
Your voice and your AI key never touch our servers; the key stays in this browser and is sent only to Google. Only your round scores are saved to track progress.