Forum Discussion

MariaMul's avatar
MariaMul
Regular Visitor
5 months ago
Solved

Fabric Key Vault connection

Hi All, I see few questions about Azure Key vault.

 

I am trying to set up the connection with a service account (with  mfa). The rbac is set to Key vault secret officer, Key vault secret user. Even the fabric workspace is set up the same on key vault rbac. I keep getting 2 errors alternating:

 

Unable to create connection for the following reason: Invalid connection credentials.

 

AADSTS70008: The provided authorization code or refresh token has expired due to inactivity. Send a new interactive authorization request for this user and resource.

 

Networking is also set to public.

 

Is it the MFA that is causing the issue? Not sure what other settings, permissions to check.

 

I have also tried to use my credentials and got the same errors. 

 

Any advice appreciated.

 

Thank you.

  • Just FYI I have managed to create it at the end. I have switched to policies, then back to rbac configuration and ensured the service principal, has the right permissions, i have added this one:

    and Key Vault Secrets User and Officer

     

    Will see if the MFA creates any issues. 

10 Replies

    • MariaMul's avatar
      MariaMul
      Regular Visitor

      Hi tayloramy ,

       

      So currently we only have a service principal with MFA. I need to explore all options so I can have enough cause for requesting app registration.

       

      Do you mean that app registration 'service principal' will not cause this issue? Currently the connection only uses oauth 2.0 so no managed/workspace identity.

      I still don't understand why i could not even create the connection with my own credentials if my rbac is set up correctly on the keyvault. Maybe I am missing something.

    • MariaMul's avatar
      MariaMul
      Regular Visitor

      Srisakthi ,

       

      I want to create a connection to key vault in fabric workspace so we can use it to retrieve secrets. The current only option in fabric is oauth 2.0. there i used service principal with MFA or my credentials with MFA. The failure occured at the point of creation of the connections. I could not even create it.

      • Srisakthi's avatar
        Srisakthi
        Icon for Super User rankSuper User

        Hi MariaMul ,

         

        Is your service principal token is valid?

        Im able to create with Service Principal without any error.

        I have public key vault, vault access configuration is set to "Vault Access Policy" and below access policy is being set for SPN

         

        Could you please verify the access settings

        Regards,

        Srisakthi

  • Hi MariaMul, 

     

    I think you may be confusing a "service account" and a "service principal". 

    A service principal is not a typical user with an email, it is an App Registration that doesn't use oauth to log in, it uses a client ID and a secret like Srisakthi described. Service principals do not have MFA. 

     

    A service account on the other hand is just a user account that does use oauth and has MFA. 

     

  • MariaMul's avatar
    MariaMul
    Regular Visitor

    Just FYI I have managed to create it at the end. I have switched to policies, then back to rbac configuration and ensured the service principal, has the right permissions, i have added this one:

    and Key Vault Secrets User and Officer

     

    Will see if the MFA creates any issues.