dzebrowitz
1 year agoAdvocate I
Status:
Planned
Invoke Pipeline Task - Workspace Identity Authentication
Currently, the Fabric Data Factory Invoke Pipeline task uses the user's credentials who saved the pipeline to then authenticate to the Azure Data Factory to execute the ADF pipeline. When that user's password is modified, the token expires and the Fabric Data Factory pipeline must be modified and saved for the Invoke Pipeline tasks to begin working again.
I would like to suggest that there be an option in the Invoke Pipeline Task to use the Fabric Workspace Identity, or specify a Service Principal for authentication to ADF.
Without this change, production Data Factory Pipelines will fail to execute after the owner changes their password.
4 Comments
- PauliusBaRegular Visitor
We face the same problem. Our use case: multiple workspaces, each of them orchestrated by their own 'slave' pipelines within those workspaces. Workspaces are interdependent and thus are orchestrated by a 'master' orchestrator pipeline in separate ws. Dependency on SSO makes the solution less reliable and less secure, as pipeline owner's principal must be granted at least CONTRIBUTOR access on all 'slave' workspaces. Workspace Identities could solve this. Furthermore, one would naturally expect workspace identities behaving as OP has mentioned. We are actively looking forward to this improvement. Keep up the good work and thanks!
- MartjanRegular VisitorI see the authentication option Workspace Identity in the connection in the connection manager for both Fabric DataPipelines and Notebooks but get authentication error when using it in the pipeline activity. Is this still unsupported? For Data Pipelines it is documented (preview). For Notebooks is not in the the supported items list in the connection setting dialog box but can be choosen anyway. Please add this as using the workspace permission model in enterprise setups at scale relies on it.
- makromerMicrosoft EmployeeStatus changed:NewtoPlanned
This feature is under development for CY26
- makromerMicrosoft EmployeeStatus changed:PlannedtoPlanned
This is under development for CY26
Recent ideas
Allow External OneLake Data Shares to Be Accepted into Multiple Fabric Item Types
Fabric External Data Sharing provides an excellent zero-copy mechanism for sharing OneLake data across tenants. However, the receiving tenant currently has to accept the share into a Lakehouse. I w...Mourak20 hours agoNew MemberNew5Views0likes0CommentsAllow OneLake Shortcut Authentication Mode to Be Changed In Place
OneLake shortcuts support passthrough and delegated authentication, but changing the authentication model currently requires deleting and recreating the shortcut. I would like shortcut authenticatio...Mourak20 hours agoNew MemberNew7Views0likes0CommentsTenant-Wide OneLake Shortcut Lineage and Impact Analysis
This is grounded in a documented limitation: shortcut lineage is currently workspace-scoped, and Microsoft specifically says lineage for shortcuts to warehouses and semantic models isn't currently av...Mourak20 hours agoNew MemberNew16Views0likes1CommentAdd an End-to-End Production Reference Architecture for Microsoft Fabric Real-Time Intelligence
I would like to see a complete end-to-end Microsoft Fabric Real-Time Intelligence reference architecture that demonstrates how the individual RTI capabilities work together in a production-oriented s...Mourak20 hours agoNew MemberNew5Views0likes0CommentsImprove CI/CD consistency for Microsoft Fabric Real-Time Intelligence Eventstreams
Microsoft Fabric Real-Time Intelligence has made strong progress with Git integration and deployment pipelines, but lifecycle management can still be inconsistent across Eventstream sources, destinat...Mourak20 hours agoNew MemberNew3Views0likes0Comments