Forum Discussion
Fabric Data Agent inaccessible from Azure WebApp using Foundry Agent
Hi AyusmanBasu0604 ,
You're encountering this issue because Microsoft Fabric Data Agents (used via Foundry) currently do not support authentication via Managed Identity or Service Principal. Instead, they require end-user identity passthrough using OAuth 2.0 on-behalf-of (OBO) flow.
Why it works locally but fails on Azure WebApp:
Locally (VS Code): You’re likely authenticated as your user identity, so Foundry can delegate the call on your behalf.
On Azure WebApp: It's running under a Managed Identity, which is not supported by Fabric Data Agents as per current platform capabilities.
Solution: Use OAuth 2.0 On-Behalf-Of (OBO) Flow
To make this work from your Azure WebApp, you must:
Authenticate the end-user (e.g., via Microsoft Entra ID login)
Obtain an access token for Microsoft Graph with required scopes
Use OBO flow in your backend Python/Streamlit app to:
Exchange the user token for a token that can access Fabric on the user's behalf
Pass this token to the Foundry agent call
If this post helps, then please appreciate giving a Kudos or accepting as a Solution to help the other members find it more quickly.
If I misunderstand your needs or you still have problems on it, please feel free to let us know. Thanks a lot!