Forum Discussion

v-kaparmar's avatar
v-kaparmar
Icon for Microsoft Employee rankMicrosoft Employee
11 months ago
Solved

Unable to Use Managed Identity Authentication in Fabric Notebook

We’re trying to use Managed Identity authentication in a Microsoft Fabric notebook to access Azure resources (such as Key Vault, Storage Account, or Application Insights), but it doesn’t seem to be working as expected.

Has anyone successfully implemented this setup? If yes, could you please share the steps or configuration details that worked for you? This will help us ensure secure and seamless access to Azure services without relying on credentials or service principals.

  • svenchio's avatar
    svenchio
    11 months ago

    Well, the your guys are out of luck, the solution being pursued is highly specific and circumvents standard integration paths

     

    Key Findings: 
    #1. Application Insights telemetry is stored in a Log Analytics workspace, and querying it requires access via Azure Monitor or Azure Data Explorer,  in other words, YOU CAN'T READ directly from App. Insights but ONLY VIA og Analytics workspace (just want to make that clear) 

    #2.  Managed Identity authentication is "supported" for querying Log Analytics via Azure Monitor APIs, but this requires 

    a) Proper RBAC role assignment (e.g., Monitoring Reader).
    b) Use of supported libraries and endpoints (e.g., azure.monitor.query or Kusto SDK) 

    #3. Fabric workspace identity is limited to OneLake shortcuts, pipelines, semantic models, or Dataflows Gen2. (Ref. Authenticate with Microsoft Fabric workspace identity - Microsoft Fabric | Microsoft Learn) 

     

    Best of lucks 

     

    Sorry to be the bearer of bad news, if you find a solution to this case, let me know! But I recommend revisiting the architecture with supported ingestion methods.

     

    Hopefully, the outcome won't prevent from you to acnoldge the help provided thus far with a thumbs up 👍 

6 Replies

  • Hi v-kaparmar  this is a BIG TOPIC, that's why perhaps knowing a more details would be very useful, in particular, what exaclty is not working as expected. Nontheless, let me try to frame at least the situation for you to understand the posibilities. 

     

    Let's take this notebook as an example, I created this notebook with the API using a Service Principal (token issued to service principal Fabric Automation as highlighted), hence, the service principal is the owner of this notebook, so, that's possible! If you need additional details as to how to do this, I can also provide assistance. 

     

     

    The next question is, how would you like this notebook to interact with, let's say, Storage Account? Then we have many options!In Fabric, the expectation on this case is either use the Lakehouse as a "bridge" via shortcuts (I belive the most powerfull) and, this shortcut uses a Connection that can be configure via a WORKSPACE  IDENTIFY as shown below.  This should be the recommended approach (or the closes one) to a managed identify auth as you described 

     

     

    But I have a gut feeling that you want the notebook to interact with azure services directly from the code, that is, without a connections? Is this what you are trying to do? and if so, why and what is the issue

     

    Let me to know to help you a bit better. 

     

  • v-dineshya's avatar
    v-dineshya
    Icon for Community Support rankCommunity Support

    Hi v-kaparmar ,

    Thank you for reaching out to the Microsoft Community Forum.

     

    Hi svenchio , Thank you for your prompt response.

     

    Hi v-kaparmar , As mentioned by svenchio , Could you please provide more details regarding your issue. It will help us to fix the issue.

     

    Regards,

    Dinesh

  • v-kaparmar's avatar
    v-kaparmar
    Icon for Microsoft Employee rankMicrosoft Employee

    Hello svenchio,

    We have a requirement to ingest Application Insights data into a Fabric Lakehouse without using Event Hub, Event Stream, or Azure Data Explorer. To achieve this, we developed a Fabric notebook that retrieves data from Application Insights using a KQL script and writes it to the Lakehouse. We successfully implemented this using certificate-based authentication; however, due to security constraints, this approach is not permitted. Since Service Principal authentication is also restricted, we are now attempting to access Application Insights data using Managed Identity authentication, but we are unable to authenticate with Managed Identity. 

    Could you please let us know the steps to access Application Insights data using Managed Identity authentication in Fabric notebook?

    Thank you!

    • svenchio's avatar
      svenchio
      Icon for Super User rankSuper User

      Well, the your guys are out of luck, the solution being pursued is highly specific and circumvents standard integration paths

       

      Key Findings: 
      #1. Application Insights telemetry is stored in a Log Analytics workspace, and querying it requires access via Azure Monitor or Azure Data Explorer,  in other words, YOU CAN'T READ directly from App. Insights but ONLY VIA og Analytics workspace (just want to make that clear) 

      #2.  Managed Identity authentication is "supported" for querying Log Analytics via Azure Monitor APIs, but this requires 

      a) Proper RBAC role assignment (e.g., Monitoring Reader).
      b) Use of supported libraries and endpoints (e.g., azure.monitor.query or Kusto SDK) 

      #3. Fabric workspace identity is limited to OneLake shortcuts, pipelines, semantic models, or Dataflows Gen2. (Ref. Authenticate with Microsoft Fabric workspace identity - Microsoft Fabric | Microsoft Learn) 

       

      Best of lucks 

       

      Sorry to be the bearer of bad news, if you find a solution to this case, let me know! But I recommend revisiting the architecture with supported ingestion methods.

       

      Hopefully, the outcome won't prevent from you to acnoldge the help provided thus far with a thumbs up 👍 

      • v-dineshya's avatar
        v-dineshya
        Icon for Community Support rankCommunity Support

        Hi v-kaparmar ,

        Could you please try the proposed solution shared by svenchio ? Let us know if you’re still facing the same issue we’ll be happy to assist you further.

         

        Regards,

        Dinesh