Forum Discussion

samgreene1's avatar
samgreene1
Icon for Resolver II rankResolver II
2 years ago

How to set up SharePoint refresh using a service account or service principal

Hi,

What are the recommended options for setting up data refresh with a service account of some type, so that it is not tied to a user's account?  

 

So far, these are options I've gathered:

1. Create a new Windows service account that is synced to our Azure tenant.  Grant access to Sharepoint list and workspace as needed.  This account needs a Power BI Pro account.  Run As with this account and configure the data source. Password can be set not to expire if needed. 

 

2. Use the service principal method.  In Azure Entra, create app registration, secret, and group. Add the group to the premium PBI workspace and admin portal for API access.  Grant rights to SharePoint list.  For dataset credentials, enter tenant, app id and secret id (shown as Service Principal Key?).  This secret will need to be updated in every dataset when the secret expires at max 2 years.

 

I just tested this method (#2) and got the error "Failed to get access_token for sharepoint URL"

 

Are there other options? Any ideas on the error I am getting? 

How would one identify the datasets that need to be updated when the secret is expiring? 

3 Replies