Forum Discussion
Scheduled Refresh Fails When Password Is Changed (Fabric Lakehouse (using sql end pt) – Import Mode)
- 7 months ago
The best practice is to use a service principal account. This accounts pass would never change and the ownership of your models stays in this.
Hi cengizhanarslan
Just wanted to confirm that, who can create this service principal account
Because I was trying to create but stuck in finding Allow service principals to use Power BI APIs (because this is not visible to me in power bi service.
I was creating in azure and there I din't find below two option
Dataset.ReadWrite.All
Workspace.ReadWrite.All
becasue of Allow service principals to use Power BI APIs is not enabled and i am not able see this option in power bi service
To create this the role should only
✔ Global Administrator
OR
✔ Power BI Service Administrator
Just want to confirm this.
Thanku so much for your time.
Hi AR_D The Power BI Admin should have the permission to grant those when you create the App in azure and enable the setting Allow service principals to use Power BI API.
You can also make use of a Workspace Identity in Fabric as the authentication for the lakehouse cloud connection.
https://learn.microsoft.com/en-us/fabric/security/workspace-identity
The other option is to use a Service Account with a password that expires yearly/never. The Service Account requires permission to the workspace or the lakehouse