Power BI (Microsoft Fabric)

The Cloudera Octopai Power BI (Microsoft Fabric) connector requires a Microsoft Entra service principal, Fabric admin tenant settings, Power BI Service API permissions, and Contributor workspace access.

Overview

Before you set up the Power BI (Microsoft Fabric) connector, ensure that you have the following:

  • Microsoft Entra application credentials: a registered service principal with a tenant ID, application (client) ID, and client secret. See Application registration (service principal).

  • Fabric admin tenant settings: settings that allow the service principal to call Fabric public APIs and access Fabric items. See Tenant settings (Fabric admin portal).

  • Power BI Service API permissions: delegated API permissions for the service principal, including Dataset.Read.All and related scopes. See Tenant-level permissions.

  • Fabric workspace permissions: the Contributor role assigned to the service principal on the target workspace. See Workspace permissions.

How this integration works

  • Cloudera Octopai connects to a single Microsoft Fabric workspace, identified by Workspace ID, in your Microsoft Entra ID (Azure AD) tenant.

  • Extraction uses service principal (client credentials) only.

  • API access is scoped by workspace access.

  • Cloudera Octopai calls Microsoft Fabric APIs and can also read Power BI content in the same workspace.

Required components on the customer side

You must have all of the following:

  • Microsoft tenant: A Microsoft Entra tenant.

  • Microsoft Fabric or Power BI enabled: Microsoft Fabric enabled in the tenant, or at a minimum enabled for the relevant capacity or workspace path.

Minimum permissions model

Because Cloudera Octopai connects to one workspace at a time, you must configure two permission layers:

  1. Tenant-level permissions allows the service principal call Fabric and Power BI APIs.

  2. Workspace-level permissions allows the service principal access the target workspace.

Application registration (service principal)

  1. In the Azure portal, open Microsoft Entra ID > App registrations, and select New registration.
  2. Give the application a name, and select Accounts in this organizational directory only.
  3. Select Register.
  4. From the application overview, record the Directory (tenant) ID and Application (client) ID.
  5. Create a Client secret under Manage > Certificates and secrets.

The Cloudera Octopai Power BI (Microsoft Fabric) connector authenticates using a Microsoft Entra service principal. The service principal is used for:

  • Microsoft Fabric REST API access
  • Power BI Service API access for workspace and item metadata

You must record the following values for configuration in Cloudera Octopai:

  • Tenant ID
  • Application (client) ID
  • Client Secret Value

Tenant settings (Fabric admin portal)

In the Fabric admin portal, enable the following settings:

  1. Open Microsoft Fabric.
  2. Select Settings, and then select Admin portal.
  3. Open Tenant settings.
  4. Find and enable Service principals can call Fabric public APIs.
  5. Find and enable Allow apps to access Fabric items.

Tenant-level permissions

In the app registration, go to Manage > API permissions, select Power BI Service, and add the following delegated permissions:

  • Dataflow.Read.All
  • Dataset.Read.All
  • Report.Read.All
  • SemanticModel.Read.All
  • Workspace.Read.All

Workspace permissions

Enabling tenant settings does not grant workspace access. You must also assign the service principal to the target workspace with the Contributor role. You need Contributor access for complete metadata extraction coverage, including:

  • Reports
  • Datasets and semantic models
  • Dataflows
  • Tables, measures, and lineage definitions

For metadata extraction (tables, measures, and lineage), you need Build and XMLA access, available with Contributor or equivalent permissions. The Viewer role is not sufficient for full metadata extraction.

Setting up Power BI (Microsoft Fabric) metadata source

Configure the metadata source on the Cloudera Octopai Client. In the New Metadata Source wizard, on Metadata Source Type, select Power BI (Microsoft Fabric).

Figure 1. Selecting Power BI (Microsoft Fabric) as the metadata source type


On Metadata Source Details, select Client Secret Authentication, and enter the following:

Figure 2. Power BI (Microsoft Fabric) metadata source details


  • Connection Name: Enter a meaningful name. The name is displayed to Cloudera Octopai platform users.
  • Application (client) ID
  • Tenant ID
  • Client Secret Value
  • Workspace ID