Hi Tom,
Just to add to what Thomas has already stated you also need to ensure that you set up a Service Principal/Managed Identity. You cannot run anything in AF without the ability to do a non-interactive signin.
Register a Microsoft Entra app and create a service principal
https://learn.microsoft.com/en-us/entra/identity-platform/howto-create-service-principal-portal
If this is helpful please accept as answer or upvote.
Best regards,
Dillon Silzer, Director | Cloudaen.com | Cloudaen Computing Solutions