Forum Discussion
Azure Key Vault References
- 1 year ago
Hi onerbreno
If your Fabric notebook isn't fetching secrets with mssparkutils.credentials.getSecret(), here are a few troubleshooting stesps to look out for:
- Make sure your Fabric workspace's managed identity has both the Key Vault Reader and Key Vault Secrets User roles assigned in Azure Key Vault's "Access Control (IAM)".
- Verify the Key Vault name and secret name in your code — they are case-sensitive. Even minor typos can cause silent failures.
- Check that the secret is active — not disabled or expired.
- If your Key Vault uses private endpoints or has public access fully disabled, Fabric won’t be able to reach it. Fabric currently doesn’t support connecting to Key Vaults through private endpoints.
- This code will only work inside a Fabric notebook — it won’t function in an external IDE or local script.
- To confirm which identity your notebook is using to call the Key Vault, run:
from notebookutils import mssparkutils
print(mssparkutils.credentials.getIdentityName()
Let me know if you need help checking any of these or interpreting what you find!
Note:For refrence check the below link for supported connectors and authentication types.
Azure Key Vault Reference overview (Preview) - Microsoft Fabric | Microsoft Learn
FYIIf the above information is helpful, please give us Kudos and mark the response as Accepted as solution.
Best Regards,
Community Support Team _ C Srikanth.
Hi willparker1,
I haven't tested it yet myself, but I would assume it's meant to work similarly to how Azure Key Vault references are used in other Azure resources. The expected format seems to follow the same structure as in, for example, App Services or Logic Apps.
You can try referencing your secret using one of the following formats:
@Microsoft.KeyVault(SecretUri=https://myvault.vault.azure.net/secrets/mysecret)
Or alternatively:
@Microsoft.KeyVault(VaultName=myvault;SecretName=mysecret)
If that works for you, feel free to mark this as the solution so others can benefit as well!
Hi Diana
Thanks so much for responding.
Unfortunately there is no option to use dynamic content in the connection set up field.
There is actually one type of connection that allows you to reference the key vault - a Blob Storage connection. In that dialog, you are given a side icon allows you to select a property from an Azure Key Vault then it replaces it with the value, (see below). However this elegant solution is unavailable on any other connection type I can find, (and no other option I can see is available to reference the Azure Key References, making them kinda useless...
Thanks
Will