<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Key Vault access without Workspace Identity in Data Engineering</title>
    <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140180#M3966</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/94286"&gt;@Eddykleinjan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tested whether the workspace identity can access the Azure Key Vault. Could you please share your results with us later? Thank you in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;BR /&gt;Jing&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2024 08:08:17 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2024-09-09T08:08:17Z</dc:date>
    <item>
      <title>Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4138852#M3958</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm ready to dive into the first real Fabric project getting data from a specific app's API. This requires using secrets to access the soure data app's API. I don't want to store these secrets in source code (insecure coding) and want to use Azure Key Vault instead. To access the Azure Key vault, the notebook process needs to have access to Azure Key Vault.&lt;/P&gt;&lt;P&gt;Now Fabric has an option to assign a identity to a workspace (workspace identity) and authorize that workspace identity to access the key vault. This souds like a solution, but the catch here is that the workspace identity is only available starting with the Fabric F64 capacity. Since pricing for F64 starts at USD 10k+ per month, that is not an option for us or our customers.&lt;/P&gt;&lt;P&gt;Also note that I would like to run this code (notebook) unattended, so an interactive authentication of the user running the notebook is not an option.&lt;/P&gt;&lt;P&gt;Anyone ran into this? Would love to hear what approach you took.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2024 13:08:12 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4138852#M3958</guid>
      <dc:creator>Eddykleinjan</dc:creator>
      <dc:date>2024-09-07T13:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4139421#M3959</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/94286"&gt;@Eddykleinjan&lt;/a&gt;, The F64 + requirement is no longer valid for Workspace Identity.&amp;nbsp; You can now create a workspace identity with any F sku.&amp;nbsp; This should allow you to accomplish what you are looking for.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Sep 2024 21:19:48 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4139421#M3959</guid>
      <dc:creator>codenamesql</dc:creator>
      <dc:date>2024-09-08T21:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140084#M3965</link>
      <description>&lt;P&gt;That's good news! Should then work ask hoped for/expected. I'll give it a try.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 07:23:24 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140084#M3965</guid>
      <dc:creator>Eddykleinjan</dc:creator>
      <dc:date>2024-09-09T07:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140180#M3966</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/94286"&gt;@Eddykleinjan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tested whether the workspace identity can access the Azure Key Vault. Could you please share your results with us later? Thank you in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;BR /&gt;Jing&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 08:08:17 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140180#M3966</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2024-09-09T08:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140269#M3967</link>
      <description>&lt;P&gt;Hi Jing,&lt;BR /&gt;Will do! For now creating a workspace identity gives an error (status: Failed). Will start a support incident on this error occurs both under a Fabric Trial capacity and a real Fabric F2 capacity.&lt;BR /&gt;Best regard, Eddy&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 08:45:21 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140269#M3967</guid>
      <dc:creator>Eddykleinjan</dc:creator>
      <dc:date>2024-09-09T08:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140914#M3971</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/94286"&gt;@Eddykleinjan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;The F64+ requirement is no longer valid. You can now create up to 1,000 workspace identities.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Important&lt;/STRONG&gt;: Currently, authentication with workspace identities, specifically for Key Vault, is not available.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Interestingly, if you have access to Key Vault with your domain account and run the notebook using the same account, you will be able to access the Key Vault secrets. You can use mssparkutils for this.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Additionally, you can create a Spark job definition using the same code (as mentioned in point 3). If you schedule and run it, it will work, using your account for authentication.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;For now, managed/workspace identity authentication for Key Vault is not functioning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;@Anonymous&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 15:09:32 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4140914#M3971</guid>
      <dc:creator>Jaimini</dc:creator>
      <dc:date>2024-09-09T15:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4141115#M3976</link>
      <description>&lt;P&gt;Perhaps you can use this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/fabric/data-engineering/notebook-utilities#credentials-utilities" target="_blank"&gt;https://learn.microsoft.com/en-us/fabric/data-engineering/notebook-utilities#credentials-utilities&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 17:24:45 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4141115#M3976</guid>
      <dc:creator>frithjof_v</dc:creator>
      <dc:date>2024-09-09T17:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4143103#M4004</link>
      <description>&lt;P&gt;Thanks for the pointer, that works! It reads the value from the Key Vault both when run interactively and when running the notebook scheduled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When running the notebook scheduled, it seems to run under the account that has created the schedule for the notebook. That way the scheduled notebook run could read the secret from the Azure Key Vault.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;test_secret = notebookutils.credentials.getSecret('https://&amp;lt;url_to_key_vault&amp;gt;/', '&amp;lt;secret_name&amp;gt;')
# Reverse the value in order to show it. Otherwise it will be shown as '[REDACTED]'
reversed_string = test_secret[::-1]
print (f"Secret value reversed: {reversed_string}")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 15:09:24 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4143103#M4004</guid>
      <dc:creator>Eddykleinjan</dc:creator>
      <dc:date>2024-09-10T15:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4143116#M4005</link>
      <description>&lt;P&gt;Hi Jing,&lt;/P&gt;&lt;P&gt;Creating the workspace identity didn't work because the workspace name had special characters in the name, a space in my case. Microsoft had identified this as a problem and will fix this.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/801050"&gt;@Jaimini&lt;/a&gt;&amp;nbsp;reported that accessing the Key Vault is not possible using the workspace identity, I chose to use the notebookutils way that&amp;nbsp;&lt;a href="https://community.fabric.microsoft.com/t5/user/viewprofilepage/user-id/437984"&gt;@frithjof_v&lt;/a&gt;&amp;nbsp;adviced. That worked; see my reply to his message.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 15:14:44 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4143116#M4005</guid>
      <dc:creator>Eddykleinjan</dc:creator>
      <dc:date>2024-09-10T15:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Key Vault access without Workspace Identity</title>
      <link>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4144425#M4017</link>
      <description>&lt;P&gt;Thank you very much!&amp;nbsp;&lt;SPAN&gt;I really appreciate the results you share!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 08:15:11 GMT</pubDate>
      <guid>https://community.fabric.microsoft.com/t5/Data-Engineering/Secure-Key-Vault-access-without-Workspace-Identity/m-p/4144425#M4017</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2024-09-11T08:15:11Z</dc:date>
    </item>
  </channel>
</rss>

