Forum Discussion
k_foxy
1 year agoFrequent Visitor
Get secret from Key Vault Web Activity
Hi I think there is a bug in Fabric, I am trying to get secret from key vault, using Web connection. I want to authenticate using service principal which is workspace identity, it has Role of Key ...
- 1 year ago
Hi k_foxy,
To target a different environment (such as test or prod), you’ll need to create a new connection that points to the appropriate Key Vault for that environment.
Once created, you can update the Web activity in your pipelines to use the new connection accordingly.Since the connection URL can’t be parameterized at the moment, switching environments requires manually changing the connection reference in the pipeline.
If this post helps, then please give us ‘Kudos’ and consider Accept it as a solution to help the other members find it more quickly.
Thank you.
rohit1991
1 year agoSuper User
Hi k_foxy ,
It sounds like you're encountering an issue with service principal authentication while attempting to retrieve a secret from Azure Key Vault using a Web activity in a Fabric pipeline. Based on the screenshot and your explanation, the error message indicates that the refresh token has expired or that OAuth authentication isn't being properly handled.
Even though the Key Vault is accessible from all networks and your service principal has the correct Key Vault Secrets User role, the Web activity doesn't seem to support full OAuth authentication using service principal credentials directly.
In Fabric, Web activity is limited in terms of providing detailed errors and may not support OAuth flows in the way needed for secure Key Vault access. Instead, consider using a Web activity with a managed identity (if available) or move the secret retrieval logic to a Dataflow Gen2 with proper Key Vault connection setup, or an Azure Function that handles the token acquisition and secret retrieval more robustly. Additionally, confirm that the service principal you're using is registered properly and that you're passing the correct token endpoint and headers in the request if doing it manually.
Passionate about leveraging data analytics to drive strategic decision-making and foster business growth.
Connect with me on LinkedIn: Rohit Kumar.