Forum Discussion
Fabric Pipeline fails to access user data function
- 4 months ago
Hi dungp,
Based on the error, this does not look like a classic workspace permission issue.
Your Service Principal may be Admin on the workspace and may even own the pipeline/UDF item, but the call is failing when notebookutils.udf.getFunctions() tries to retrieve the UDF metadata through the Fabric metadata API.
According to the current User Data Functions limitations, accessing Fabric items or data sources using a Service Principal is not currently supported in some UDF scenarios. So the 401 is likely caused by the execution identity/context rather than by missing workspace permissions.
A few things I would check :
1. Test the same pipeline/notebook with an interactive user identity.
2. Confirm whether the issue only happens when the pipeline runs under the Service Principal.
3. If yes, this is probably a current product limitation rather than a misconfiguration.
4. As a workaround, you may need to run the notebook/pipeline under a user identity, or move this logic outside the UDF call until SPN support is fully available for this execution path.Docs:
- NotebookUtils UDF getFunctions : https://learn.microsoft.com/en-us/fabric/data-engineering/notebookutils/notebookutils-user-data-function
- User Data Functions limitations : https://learn.microsoft.com/en-us/fabric/data-engineering/user-data-functions/user-data-functions-service-limitsHope this helps clarify the root cause.
If this helped, please consider marking it as a solution so others can find it more easily. - 4 months ago
Thanks a lot for your answer Tamanchu. The pipeline runs without issue under my identity, so i believe the issue only happens when it runs under the Service Principle. I've reached out to Microsoft for the confirmation, if thats the issue then i will mark your answer as solution!
Regarding working around, i reverted changes back to using the %run maggic command with notebooks to load the logics instead of using UDF. I think using UDF is a proper and standard way to handle shared codes, but it seems we need to wait a bit before we can fully leverage this feature.
Thanks again!
Thanks a lot for your answer Tamanchu. The pipeline runs without issue under my identity, so i believe the issue only happens when it runs under the Service Principle. I've reached out to Microsoft for the confirmation, if thats the issue then i will mark your answer as solution!
Regarding working around, i reverted changes back to using the %run maggic command with notebooks to load the logics instead of using UDF. I think using UDF is a proper and standard way to handle shared codes, but it seems we need to wait a bit before we can fully leverage this feature.
Thanks again!
Hi dungp,
Is your service principal allowed to access Fabric APIs? THat is a Fabric tenant setting that your Fabric Administrator can help with.
Also ensure that your service principal has permissions on the UDF.
- dungp4 months agoRegular Visitor
Thanks tayloramy for hopping in
- Is your service principal allowed to access Fabric APIs? Yes
- Also ensure that your service principal has permissions on the UDF: Yes, Im aware of this. The service principal has both wokspace admin and read/write/execute permission from the UDF
Im discussing this with the Fabric support team. Its likely a limitation of the UDF when authenticating with service principal, but still need a confirmation from them. If thats the case, then i'll put their answer here for anyone to be aware of it!