ADF API Call from ACI via Ev2

Ryan Pethel 6 Reputation points Microsoft Employee
2022-03-31T19:11:38.763+00:00

We’re using ShellExtension to deploy ADF configurations, executing PowerShell scripts via ACI, and we’re seeing the following error:

Status Code: Unauthorized Error Code Unauthorized
Error Message: Client IP not authorized to access the API.
Please ensure you are on corpnet, or that your IP is on an allowlist for the activities in your pipeline.

Request Id: 2de33394-657c-4e86-a675-e9227dfad6fb
Time: (Utc):03/30/2022 21:28:50

Ev2 run: Ev2 Portal - Dashboard (azure.net)

We believe the client is the ACI (Linux container) calling ADF API but is being denied access here.

Instead of requiring the ACI to have a Corp IP address, is there a way to check if the deployment request is coming from a subscription under the Microsoft AME tenant? If so, can we allow it to use the SCOPE extensions?

Any help would be much appreciated!

Azure Data Factory
Azure Data Factory
An Azure service for ingesting, preparing, and transforming data at scale.
11,625 questions
{count} vote

1 answer

Sort by: Most helpful
  1. PRADEEPCHEEKATLA 90,641 Reputation points Moderator
    2022-04-04T10:54:16.44+00:00

    Hello @Ryan Pethel ,

    Welcome to the MS Q&A platform.

    Unfortunately, we can not whitelist the EV2 trigger process at this time. However, the Cosmos/ADLA/ADLS team is in the process of deploying a fix that will eliminate the corpnet only access restriction that is causing this issue.

    We will update this thread once it's available.

    Hope this will help. Please let us know if any further queries.

    ------------------------------

    • Please don't forget to click on 130616-image.png or upvote 130671-image.png button whenever the information provided helps you. Original posters help the community find answers faster by identifying the correct answer. Here is how
    • Want a reminder to come back and check responses? Here is how to subscribe to a notification
    • If you are interested in joining the VM program and help shape the future of Q&A: Here is how you can be part of Q&A Volunteer Moderators
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.