AAS refresh failure via ADF

Priya Jha 871 Reputation points

HI All,

I am following the below blog to process AAS via managed identity:

The only change that i implemented is rather than providing the ADF individual access, i added that ADF within an AD group and added that AD Group as Analysis service admin, similar to the below blog initial step:

I am getting Unauthorized access when adding the ADF via AD Group but it is working properly when the ADF is explicitly added as AAS Admin.

The same aspect is happening via Service Principal authentication as well.

Any reason why managed identity is work fine via group aspect in PowerBI refresh and not working for AAS refresh?

Why is there an explicit need to add the individual users and not propagated via AD group?

Azure Analysis Services
Azure Analysis Services
An Azure service that provides an enterprise-grade analytics engine.
444 questions
Azure Data Factory
Azure Data Factory
An Azure service for ingesting, preparing, and transforming data at scale.
10,152 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ShaikMaheer-MSFT 38,326 Reputation points Microsoft Employee

    Hi @Priya Jha ,

    Thank you for posting query in Microsoft Q&A Platform.

    Usually, Unauthorized access error will come when the identity which is getting used will not have sufficient permissions to perform task.

    In case of PowerBI the setting explicitly called out to use security groups. Hence there we should use security groups only. Please check below screenshot.


    In case of AAS kindly consider adding managed Identity itself as AAS admin.

    Hope this helps. Please let me know for any queries.

    Please consider hitting Accept Answer button. Accepted answers help community as well.