You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ADOMD连接PowerBI XMLA端点时遇无效令牌类型错误

Power BI XMLA端点ADOMD连接失败问题

我能通过SSMS和DAX Studio连接目标XMLA端点,但使用C#的ADOMD库无法建立连接。测试用的C#代码如下:

using Microsoft.AnalysisServices.AdomdClient;
using Azure.Identity;

class Program
{
    static async Task Main(string[] args)
    {
        // Configuration
        string xmlaEndpoint = "powerbi://api.powerbi.com/v1.0/myorg/<my org>";
        string scope = "https://analysis.windows.net/powerbi/api/.default";

        try
        {
            // Step 1: Acquire an access token using DefaultAzureCredential
            Console.WriteLine("Acquiring access token using Azure Default Credential...");
            var credential = new InteractiveBrowserCredential();
            var tokenRequestContext = new Azure.Core.TokenRequestContext(new[] { scope });
            var accessToken = (await credential.GetTokenAsync(tokenRequestContext)).Token;
            Console.WriteLine("Access token acquired successfully.");

            // Step 2: Create connection string using the access token
            string connectionString = $"Data Source={xmlaEndpoint};Authentication=Bearer;Password={accessToken};";

            // Step 3: Connect to the XMLA endpoint and execute a query
            using (AdomdConnection connection = new AdomdConnection(connectionString))
            {
                Console.WriteLine("Opening connection...");
                connection.Open();

                string query = "EVALUATE TOPN( 500, Invoices )";
                using (AdomdCommand command = new AdomdCommand(query, connection))
                {
                    Console.WriteLine("Executing query...");
                    using (AdomdDataReader reader = command.ExecuteReader())
                    {
                        while (reader.Read())
                        {
                            Console.WriteLine(reader["Name"]);
                        }
                    }
                }

                connection.Close();
                Console.WriteLine("Connection closed successfully.");
            }
        }
        catch (Exception ex)
        {
            Console.WriteLine($"Error: {ex.Message}");
        }
    }
}

运行代码时抛出异常:
Error: MWC token validation failed: Invalid Token type, expected ServiceToken but got AadBasedToken

使用的凭据与SSMS、DAX Studio连接时完全一致,且代码生成的访问令牌可正常调用PowerBI REST API,不清楚SSMS和DAX Studio的处理方式有何不同。


解决方案

核心原因

ADOMD库连接Power BI XMLA端点时,需要的是针对Power BI服务的特定令牌格式,直接使用Azure Identity获取的Bearer令牌不符合要求,而SSMS/DAX Studio内部会自动处理令牌的转换逻辑。

修复步骤

  • 替换身份验证方式:不要手动获取令牌后用Bearer认证,改用ADOMD内置的ActiveDirectoryInteractive认证方式,让库自行处理令牌获取和转换。
  • 调整连接字符串:移除手动令牌相关的配置,直接指定认证类型和必要参数。

修改后的代码:

using Microsoft.AnalysisServices.AdomdClient;

class Program
{
    static void Main(string[] args)
    {
        // Configuration
        string xmlaEndpoint = "powerbi://api.powerbi.com/v1.0/myorg/<my org>";

        try
        {
            // 使用ActiveDirectoryInteractive认证,由ADOMD库处理令牌逻辑
            string connectionString = $"Data Source={xmlaEndpoint};Authentication=ActiveDirectoryInteractive;";

            using (AdomdConnection connection = new AdomdConnection(connectionString))
            {
                Console.WriteLine("Opening connection...");
                connection.Open();

                string query = "EVALUATE TOPN( 500, Invoices )";
                using (AdomdCommand command = new AdomdCommand(query, connection))
                {
                    Console.WriteLine("Executing query...");
                    using (AdomdDataReader reader = command.ExecuteReader())
                    {
                        while (reader.Read())
                        {
                            Console.WriteLine(reader["Name"]);
                        }
                    }
                }

                connection.Close();
                Console.WriteLine("Connection closed successfully.");
            }
        }
        catch (Exception ex)
        {
            Console.WriteLine($"Error: {ex.Message}");
        }
    }
}

关键说明

  • ActiveDirectoryInteractive认证会自动弹出交互式登录窗口,和SSMS/DAX Studio的登录流程一致,确保获取到符合要求的服务令牌。
  • 如果需要非交互式认证(比如服务账号),可以使用ActiveDirectoryPassword或ActiveDirectoryServicePrincipal认证类型,同样由ADOMD库处理令牌转换。

内容的提问来源于stack exchange,提问作者Bryan Batchelder

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 06:34:59