Forum Discussion
grant_type must be "password" and app level permissions
- 8 years ago
We use a service account that has access to PowerBI for this. We have MFA turned on almost all accounts, but off for service accounts.
It apears to be true that one needs the password grant type.
And for extra fun, the AAD library no longer supports it. "UserCredential" is no lnoger there.
So what you must do is issue a regular old HTTPS POST to the authority URL, and a body like this:
string authBody = $@" grant_type = password &resource ={WebUtility.UrlEncode(resourceString)} &username ={WebUtility.UrlEncode(username)} &password ={WebUtility.UrlEncode(password)} &client_id ={clientId} &client_secret={ WebUtility.UrlEncode(secret)}";With this information, becuase you're including a client secret, there will be no prompt necessary.
Good luck.
-e
We use a service account that has access to PowerBI for this. We have MFA turned on almost all accounts, but off for service accounts.
It apears to be true that one needs the password grant type.
And for extra fun, the AAD library no longer supports it. "UserCredential" is no lnoger there.
So what you must do is issue a regular old HTTPS POST to the authority URL, and a body like this:
string authBody = $@"
grant_type = password
&resource ={WebUtility.UrlEncode(resourceString)}
&username ={WebUtility.UrlEncode(username)}
&password ={WebUtility.UrlEncode(password)}
&client_id ={clientId}
&client_secret={ WebUtility.UrlEncode(secret)}";With this information, becuase you're including a client secret, there will be no prompt necessary.
Good luck.
-e
Not true, you can use client_credentials. But note, many endpoints are not allowed (not documented) and note this especially: python - Power BI Rest API Requests Not Authorizing as expected - Stack Overflow
And you need to grant your Service Principal access to the workspace
And alter the api settings in the Admin portal
- WheresWally3 years ago
Helper III
Hi Sam,
I have this working and giving me a bearer code. I can use it to access things like the activity logs.
I can't manage to get it to post rows to a push dataset though.
I can push rows to the dataset if I grab the bearer code from my login using the 'try this' page, so I know my API push setup is all correct. I have all the admin settings as you've described and have the dataset and workspace (admin) shared to the application and the group it's in.
Any ideas about what else might be getting in the way? Thanks
- WheresWally3 years ago
Helper III
Wait..I just read your linked stack overflow question and it's exactly what I needed. Now I need to go and remove powerbi permissions from the application. How conterintuitive. Hope it works.
- WheresWally3 years ago
Helper III
Oh no, I just read it again. Read only...
Can't use applications to post rows....ughhhhh. Does anyone here have a method they use for posting rows via API that works? I'd like to use an application secret type setup because the current method (Knime ETL send to powerbi node, requires microsoft authentication via a user).