Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Enhance your career with this limited time 50% discount on Fabric and Power BI exams. Ends August 31st. Request your voucher.

Reply
ashvini-dure
Frequent Visitor

AAD Token Generation

Hi,

 

I need help regarding AAD token generation. As per suggestion, I have decoded token in jwt.ms . Refer screenshot for same.

Getting "Tenant.ReadWrite.All" still getting 403 clusterdetails error while loading Power BI report in edit mode.

ashvinidure_0-1748842211696.png

 

1 ACCEPTED SOLUTION
v-sgandrathi
Community Support
Community Support

Hi @ashvini-dure,

Thank you for your detailed input @ibarrau.

To confirm, the 403 error despite having Tenant.ReadWrite.All usually indicates a configuration issue. Please ensure that the "Embed content in apps" setting is enabled in the Fabric Admin Portal under Tenant Settings. If you're using a Master User approach, make sure Admin Consent has been granted for the Tenant.ReadWrite.All permission in Azure Active Directory. For Service Principal authentication, verify that the same permission is granted and that the "Service principals can call Fabric public APIs" setting is enabled in the Fabric Admin Portal. 

 

Hope my suggestion gives you good idea, if you have any more questions, please feel free to ask we are here to help you.
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

 

Thank you.

 

 

View solution in original post

7 REPLIES 7
v-sgandrathi
Community Support
Community Support

Hi @ashvini-dure,

Thank you for your detailed input @ibarrau.

To confirm, the 403 error despite having Tenant.ReadWrite.All usually indicates a configuration issue. Please ensure that the "Embed content in apps" setting is enabled in the Fabric Admin Portal under Tenant Settings. If you're using a Master User approach, make sure Admin Consent has been granted for the Tenant.ReadWrite.All permission in Azure Active Directory. For Service Principal authentication, verify that the same permission is granted and that the "Service principals can call Fabric public APIs" setting is enabled in the Fabric Admin Portal. 

 

Hope my suggestion gives you good idea, if you have any more questions, please feel free to ask we are here to help you.
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

 

Thank you.

 

 

Hi @v-sgandrathi ,

 

We have not moved to Fabric mode. Can you provide a sollution without Fabric enabled.

 

Thank you.

Hi @ashvini-dure,

 

As you're not using Microsoft Fabric, the issue likely lies in the configuration of the app or user within the classic Power BI setup. First, confirm whether the permission is delegated or application-based, as edit mode typically requires delegated permissions tied to a signed-in user and ensure that admin consent has been granted in Azure Active Directory for the necessary scopes, such as Tenant.ReadWrite.All, Report.ReadWrite.All, and Dataset.ReadWrite.All.
Next, verify that the user or service principal has the correct Power BI workspace access with edit rights and an appropriate role (Admin or Member).
If you're using a service principal, check that it is enabled for API access in the Power BI Admin Portal. For a master user, confirm that it is licensed (Power BI Pro or Premium) and is part of the workspace. Finally, if the setup appears correct, use browser developer tools or Fiddler to inspect the API response for more details, which can indicate the exact permission or configuration that is missing.

 

Thank you.

Hi @ashvini-dure,

 

Since we haven't heard back from you yet, I'd like to confirm if you've successfully resolved this issue or if you need further help?
If you've already resolved the issue, you can mark the helpful reply as a "solution" so others know that the question has been answered and help other people in the community. Thank you again for your cooperation!
If you still have any questions or need more support, please feel free to let us know. We are more than happy to continue to help you.

 

Thank you.

Hi @ashvini-dure,

 

As we did not get a response, may I know if the above reply could clarify your issue, or could you please help confirm if we may help you with anything else?

 

And if the provided information meets your requirements, you can Accept the solution and also give Kudos on that reply. It helps other users who are searching for this same information and find the information.

 

Your understanding and patience will be appreciated.

Hi @v-sgandrathi , thank you for your support.

ibarrau
Super User
Super User

Hi. First check that "Embed content in Apps" setting from the Fabric Admin Portal Tenant settings is enabled. Then, it depends on how you are using the credentials. If you are connecting with master users make sure the "Grant Admin Conset" has been applied to the Tenant.ReadWrite.All. If you are using Service Principal then you have to turned on "Service Principals can call Fabric public APIs" at Fabric Admin portal.

I hope that helps,


If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

Happy to help!

LaDataWeb Blog

Helpful resources

Announcements
July 2025 community update carousel

Fabric Community Update - July 2025

Find out what's new and trending in the Fabric community.

July PBI25 Carousel

Power BI Monthly Update - July 2025

Check out the July 2025 Power BI update to learn about new features.