Forum Discussion

Bhargava05's avatar
Bhargava05
Resolver II
10 months ago
Solved

Dataflow Gen2 CI/CD Enabled โ€“ Refresh Fails for Non-Owner with Admin/Contributor Access

Hi team, I created a Dataflow Gen2 in Microsoft Fabric with the CI/CD option enabled. When I trigger a refresh as the owner, it completes successfully. However, when a non-owner user with Admin or C...
  • AntoineW's avatar
    10 months ago

    Hello Bhargava05,

     

    When CI/CD (Git integration) is enabled in a Fabric workspace:

    • The Dataflow Gen2 definition is versioned and stored as JSON in the Git repository.

    • Connection credentials, however, are not stored in Git (for security reasons).

    • The credentials are instead stored per user in the Fabric service layer.

    ๐Ÿ‘‰ This means only the user who originally authenticated the data source (the dataflow owner) has valid credentials linked to that Git-bound dataflow instance.

     

    Solutions : 

    Option 1 โ€“ Re-authenticate the data source as the non-owner

    1. Have the non-owner open the Dataflow Gen2 in Edit mode.

    2. Go to Settings โ†’ Connections.

    3. Select the data source โ†’ click Edit credentials.

    4. Enter their own credentials and save.

    ๐Ÿ”น Drawback: each admin/contributor must do this individually (credentials are not shared).


    **Option 2 โ€“ Use a Service Principal (recommended)

    If your source supports Azure AD App/Service Principal authentication (SQL, Lakehouse, OneLake, etc.):

    1. Create a service principal in Entra ID.

    2. Grant it access to the data source.

    3. In the Dataflow connection โ†’ choose โ€œSign in with Service Principalโ€.

    โœ… Result: credentials are now tenant-level, not user-level, so any workspace admin can trigger refreshes successfully.

     

    Hope it can help you !

    Best regards,

    Antoine