Forum Discussion
Service principal for dataset datasource credential
- 1 year ago
Hi msprog,
Apologize for the inconvenience caused. Thank you for your follow-up, that is a good question. We acknowledge that this limitation is not clearly documented at present.While Power BI Service does let you enter Service Principal details (like tenant ID, client ID, and secret) in the credentials dialog, it’s important to note that not all connectors support SPN-based authentication behind the scenes.
In your case, both the Web and SharePoint Folder connectors rely on delegated OAuth2, which means they expect a signed in user contex.
If using a Service Principal is a must for your scenario, here are a couple of potential workarounds:
- Use the Microsoft Graph API in combination with Web.Contents() and an access token obtained via the client credentials flow (SPN). This would require setting up a gateway to support the refresh in Power BI Service.
- Alternatively, you could build a custom connector that securely handles SPN token acquisition and integrates with your data source.
Kindly refer to the below mentioned documentation links:
OAuth 2.0 client credentials flow on the Microsoft identity platform - Microsoft identity platform | Microsoft Learn
Web.Contents - PowerQuery M | Microsoft LearnIf you have any questions, please do not hesitate to contact us, and we will be happy to assist you.
Thank you for using the Microsoft Community Forum.
Hi msprog,
Thank you for reaching out to the Microsoft Fabric Community Forum, and we appreciate the detailed context you’ve provided along with the steps you've already taken.
Based on your scenario, you are right to question whether Service Principal (SPN) authentication is supported for the Web and SharePoint Folder connectors in the Power BI Service. Below is a breakdown of the current limitations and recommended alternatives to help resolve the issue.
Power BI does not currently support using a Service Principal (i.e., app-only token) for authenticating Web or SharePoint Folder connectors when configuring dataset refresh credentials in the Power BI Service. These connectors are designed to use OAuth2 delegated authentication, which requires signing in with a user account. Currently, the credential dialog in Power BI Service does not support entering a client ID/secret for app-only access.
Using SharePoint Folder in Power BI
Authentication in desktop apps - Power Query | Microsoft Learn
Use Delegated OAuth2 (User Identity): As a supported approach, configure the dataset credentials using OAuth2 and sign in with a user account that has access to the SharePoint site. You can use Web.Contents() in Power Query with a manually obtained token via client credentials flow.
Get file content from SharePoint using Microsoft Graph
Access token request with client credentials flow
Web.Contents - PowerQuery M | Microsoft Learn
Please note that this would typically require: Custom M code to acquire and use the token. A gateway to support token logic and bypass test connection issues.
Use a Custom Connector + Gateway (Enterprise Solution): You can develop a Power Query Custom Connector that handles SPN authentication using the Graph API, and deploy it via an On-premises Data Gateway.
If this post helps, then please give us ‘Kudos’ and consider Accept it as a solution to help the other members find it more quickly.
Thank you for using Microsoft Community Forum.
Thanks for this input v-kpoloju-msft ,
Is there any MSFT doc that clearly mentions this limitation with Web and Sharepoint folder connector? if there is, can you please point me to that,
Also you mention that Currently, the credential dialog in Power BI Service does not support entering a client ID/secret for app-only access. Sorry what do you mean by this?, I can enter values for tenant id, Service Principal Id and Service Principal key. Please can you explain
thanks
- v-kpoloju-msft1 year agoCommunity Support
Hi msprog,
Apologize for the inconvenience caused. Thank you for your follow-up, that is a good question. We acknowledge that this limitation is not clearly documented at present.While Power BI Service does let you enter Service Principal details (like tenant ID, client ID, and secret) in the credentials dialog, it’s important to note that not all connectors support SPN-based authentication behind the scenes.
In your case, both the Web and SharePoint Folder connectors rely on delegated OAuth2, which means they expect a signed in user contex.
If using a Service Principal is a must for your scenario, here are a couple of potential workarounds:
- Use the Microsoft Graph API in combination with Web.Contents() and an access token obtained via the client credentials flow (SPN). This would require setting up a gateway to support the refresh in Power BI Service.
- Alternatively, you could build a custom connector that securely handles SPN token acquisition and integrates with your data source.
Kindly refer to the below mentioned documentation links:
OAuth 2.0 client credentials flow on the Microsoft identity platform - Microsoft identity platform | Microsoft Learn
Web.Contents - PowerQuery M | Microsoft LearnIf you have any questions, please do not hesitate to contact us, and we will be happy to assist you.
Thank you for using the Microsoft Community Forum.- v-kpoloju-msft1 year agoCommunity Support
Hi msprog,
May I ask if you have resolved this issue? If so, please mark the helpful reply and accept it as the solution. This will be helpful for other community members who have similar problems to solve it faster.
Thank you.