Forum Discussion
Anonymous
1 year agoNot applicable
Failed to get User Auth access token - Notebook, Lookup and Get Metadata Activities Failing
I delivered a set of pipelines to the client two months ago but they are reporting that the pipelines are failing. When I open up the pipeline and check the failed run, it fails when running activiti...
- 1 year ago
Hi Anonymous,
You're right most documentation around app registration is general to Microsoft Entra ID.
- Register an App in Entra ID
Choose the "Client credentials" flow (either certificate or client secret).
Save the Application (client) ID, Directory (tenant) ID, and the client secret or certificate details. - Grant the App Access to the Fabric Workspace
In the Fabric workspace, go to Settings > Permissions.
Add the Service Principal (App ID) as a Contributor or higher role depending on access needs. - Configure the Linked Services
In your Data Pipeline or Notebook Linked Service, choose Service Principal authentication.
Provide the tenant ID, client ID, and client secret.
- Use Azure Key Vault
Store the client secret securely in Azure Key Vault.
Reference the secret from the Linked Service to avoid hardcoding sensitive data.
- If Azure Key Vault is unavailable, you can enter secrets directly into the Linked Service configuration. Although this method works, it is less secure and not recommended for production environments. For improved security and maintainability, it is advisable to use Azure Key Vault whenever possible.
- The Service Principal doesn’t "own" the pipelines in the traditional sense, but once it's configured for authentication, all activities (e.g., Notebooks, Lookups, Get Metadata) will run using its credentials. This effectively decouples the pipelines from user-based tokens, ensuring long-term stability even if user accounts are removed or passwords are changed.
If this post helps, then please give us ‘Kudos’ and consider Accept it as a solution to help the other members find it more quickly.
Thank you.
- Register an App in Entra ID
Anonymous
1 year agoNot applicable
Thank you very much! I'm looking up the documentation for your next steps and I'm not sure where to start:
- I'm checking the documentation to "register an app in Microsoft Entra ID, assign it the necessary roles" and I'm checking https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app?tabs=certificate%2Cexpose-a-web-api but I don't see anything specific for Fabric? How would I configure this for a Fabric workspace
- What happens if the client doesn't have an Azure Key Vault?
- When you refer to "The client should reconfigure all pipeline authentication using a Service Principal or a Managed Identity (if supported)." does this mean the Fabric account with the Service Principal/Managed Identity needs to perform a takeover on the developed items?
v-saisrao-msft
Community Support
1 year agoHi Anonymous,
You're right most documentation around app registration is general to Microsoft Entra ID.
- Register an App in Entra ID
Choose the "Client credentials" flow (either certificate or client secret).
Save the Application (client) ID, Directory (tenant) ID, and the client secret or certificate details. - Grant the App Access to the Fabric Workspace
In the Fabric workspace, go to Settings > Permissions.
Add the Service Principal (App ID) as a Contributor or higher role depending on access needs. - Configure the Linked Services
In your Data Pipeline or Notebook Linked Service, choose Service Principal authentication.
Provide the tenant ID, client ID, and client secret.
- Use Azure Key Vault
Store the client secret securely in Azure Key Vault.
Reference the secret from the Linked Service to avoid hardcoding sensitive data.
- If Azure Key Vault is unavailable, you can enter secrets directly into the Linked Service configuration. Although this method works, it is less secure and not recommended for production environments. For improved security and maintainability, it is advisable to use Azure Key Vault whenever possible.
- The Service Principal doesn’t "own" the pipelines in the traditional sense, but once it's configured for authentication, all activities (e.g., Notebooks, Lookups, Get Metadata) will run using its credentials. This effectively decouples the pipelines from user-based tokens, ensuring long-term stability even if user accounts are removed or passwords are changed.
If this post helps, then please give us ‘Kudos’ and consider Accept it as a solution to help the other members find it more quickly.
Thank you.