Forum Discussion
Fabric Key Vault connection
Hi All, I see few questions about Azure Key vault.
I am trying to set up the connection with a service account (with mfa). The rbac is set to Key vault secret officer, Key vault secret user. Even the fabric workspace is set up the same on key vault rbac. I keep getting 2 errors alternating:
Unable to create connection for the following reason: Invalid connection credentials.
AADSTS70008: The provided authorization code or refresh token has expired due to inactivity. Send a new interactive authorization request for this user and resource.
Networking is also set to public.
Is it the MFA that is causing the issue? Not sure what other settings, permissions to check.
I have also tried to use my credentials and got the same errors.
Any advice appreciated.
Thank you.
Just FYI I have managed to create it at the end. I have switched to policies, then back to rbac configuration and ensured the service principal, has the right permissions, i have added this one:
and Key Vault Secrets User and Officer
Will see if the MFA creates any issues.
10 Replies
- tayloramy
Super User
Hi MariaMul,
The recommended path for using KVs is to use a service principal/worksapce identity instead of a user account to access them. This will get around any pesky mfa.
See Configure AKV references - Microsoft Fabric | Microsoft Learn
- MariaMulRegular Visitor
Hi tayloramy ,
So currently we only have a service principal with MFA. I need to explore all options so I can have enough cause for requesting app registration.
Do you mean that app registration 'service principal' will not cause this issue? Currently the connection only uses oauth 2.0 so no managed/workspace identity.
I still don't understand why i could not even create the connection with my own credentials if my rbac is set up correctly on the keyvault. Maybe I am missing something.
- MariaMulRegular Visitor
I want to create a connection to key vault in fabric workspace so we can use it to retrieve secrets. The current only option in fabric is oauth 2.0. there i used service principal with MFA or my credentials with MFA. The failure occured at the point of creation of the connections. I could not even create it.
- Srisakthi
Super User
Hi MariaMul ,
Is your service principal token is valid?
Im able to create with Service Principal without any error.
I have public key vault, vault access configuration is set to "Vault Access Policy" and below access policy is being set for SPN
Could you please verify the access settings
Regards,
Srisakthi
- tayloramy
Super User
Hi MariaMul,
I think you may be confusing a "service account" and a "service principal".
A service principal is not a typical user with an email, it is an App Registration that doesn't use oauth to log in, it uses a client ID and a secret like Srisakthi described. Service principals do not have MFA.
A service account on the other hand is just a user account that does use oauth and has MFA.
- MariaMulRegular Visitor
Just FYI I have managed to create it at the end. I have switched to policies, then back to rbac configuration and ensured the service principal, has the right permissions, i have added this one:
and Key Vault Secrets User and Officer
Will see if the MFA creates any issues.