Forum Discussion

harsh_chandra's avatar
harsh_chandra
New Member
2 days ago

403 GraphQL API

Hi Team,

We are integrating the Microsoft Fabric API for GraphQL with Salesforce. Our requirement is to retrieve Account data from Microsoft Fabric/Data Lake into Salesforce based on the Account_ID.

Current Implementation

  1. We have successfully generated a Microsoft Entra ID access token using: Tenant ID, Application (Client) ID & Client Secret
  2. We are then calling the generated Fabric GraphQL API: https://graphql.fabric.microsoft.com/v1/workspaces/<workspaceid>/graphqlapis/<graphqlid>/graphql
  3. Sample GraphQL request: query { accounts(first: 10) { items { Account_ID } } }
  4. Request headers: Authorization: Bearer <ACCESS_TOKEN> Content-Type: application/json

Issue

The GraphQL API call is returning HTTP 403 Forbidden. The response body is empty/null, while the response headers contain the following error:

X-PowerBI-Error-Info: ServicePrincipalIsNotAllowedByTenantAdminSwitch

Based on this error, it appears that the service principal is being blocked by a Fabric tenant-level setting.

Questions

Could you please confirm the following:

  1. Is the above GraphQL endpoint correct for calling a Fabric API for GraphQL using a Microsoft Entra service principal?
  2. Where exactly should service-principal access be enabled - Microsoft Fabric Admin Portal / Tenant Settings or Power BI Admin Portal / Tenant Settings or Microsoft Entra ID / Azure Portal

We would appreciate your guidance on the required tenant-level configuration and Fabric permissions so that we can proceed with the Salesforce integration.

Thanks,

Harsh Chandra

No RepliesBe the first to reply