Forum Discussion
Service Principal authentication (for Graph API) without hardcoded credentials
- 1 year ago
Ok, for anyone in the future wanting a (sort-of) solution...
It turns out that service principal authentication via the UI in dataflows will work for beta graph API endpoints, but will not work for v1.0. For example, use https://graph.microsoft.com/beta/users instead of https://graph.microsoft.com/v1.0/users.We are changing all queries our queries use the beta endpoints. So far no particular issues, though of course there are some minor risks of things changing when using the beta endpoints. That being said, Microsoft themselves use beta endpoints for production purposes, so they should be quite stable.
When setting it up, make sure that you are specifying the connection for either the full endpoint or for https://graph.microsoft.com/beta, not https://graph.microsoft.com as this won't work. Refer screenshot below.
Hi paddy_135
You can consider to use Python to get the token, then set it as a paramater to Power query, you can refer to the following link about it.
oauth - Using Python to retrieve access token for Power BI's Rest API? - Stack Overflow
Power BI REST API with Python and Microsoft Authentication Library (MSAL)
Best Regards!
Yolo Zhu
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly
- paddy_1351 year agoFrequent Visitor
Hi Yolo
Thanks for taking the time to reply. However, I don't think this solves the issue - the hardcoded credentials would just be moved to wherever the python code is defined. Unless I misunderstood your suggestion?
Thanks