Get Secret from Azure Key Vault using Fabric Workspace Identity
Users can access key vault secrets using notebookutils.credentials.getSecret. This is based purely on the user's access (or object owner's access, if the notebook is being run in a pipeline). In larger organizations, managing access at the individual level is not scalable. It would be preferable to associate key vault privileges with a service principal so that connections keep running if a particular user leaves the business.
The workspace identity is an obvious candidate to be given key vault permissions. While this is technically possible - we can add key vault privileges to a workspace identity's associated entra ID app service principal - the service principal's credentials are not used by the notebookutils.credentials.getSecret method. (At least based on my current understanding - this seems to be a known limitation if you read related posts in the Fabric user forums as of August 2025).
Please make it possible to access key vault secrets using workspace identities.
2 Comments
- gpetritesFrequent VisitorIt is crazy how many places in Fabric the workspace identity can NOT be used. For a service intended to support enterprises, this dependency on user identities is unacceptable.
- sean_cochran
Resolver I
For anyone who liked this idea - there is now a workaround. Notebook connections can be used in a pipeline to force an SP's credentials to be used when making a key vault call. Not perfect, but it's something.
Recent ideas
Set SQL analytics endpoint access mode (User's identity) via REST API and Terraform
The SQL analytics endpoint enforces OneLake security only in User's identity access mode. The only documented way to choose the mode is the Security tab in the portal (Data access mode settings). Not...smorimoto1 hour agoNew MemberNew1View0likes0CommentsFabric Copy Jobs desperately need basic editability after creation.
Requiring users to recreate an entire Copy Job just to change something as fundamental as the source connection or connection URL is unnecessarily restrictive and creates significant maintenance over...mpersha22 hours agoRegular VisitorNew6Views0likes0Comments