You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Data Factory托管实例数据流读取ADLS Gen2 JSON文件遇403权限错误

问题:ADF数据流读取ADLS Gen2 JSON文件触发403权限错误

场景说明

  • 通过API将JSON文件下载至ADLS Gen2存储账户的指定路径:container\firstDir\SecondDir\myfile.json
  • 使用的数据集链接服务与之前作为接收器时完全一致
  • 构建数据流读取该JSON文件并扁平化存入数据表时,触发如下403权限错误:

at Source 'source1': Operation failed: "This request is not authorized to perform this operation.", 403, HEAD, https://myconnection/?upn=false&action=getAccessControl&timeout=90 When using Managed Identity(MI)/Service Principal(SP) authentication

  1. For source: In Storage Explorer, grant the MI/SP at least Execute permission for ALL upstream folders and the file system, along with Read permission for the files to copy. Alternatively, in Access control (IAM), grant the MI/SP at least the Storage Blob Data Reader role.
  2. For sink: In Storage Explorer, grant the MI/SP at least Execute permission for ALL upstream folders and the file system, along with Write permission for the sink folder. Alternatively, in Access control (IAM), grant the MI/SP at least the Storage Blob Data Contributor role. Also please ensure that the network firewall settings in the storage account are configured correctly as turning on firewall rules for your storage account blocks incoming requests for data by default, unless the requests originate from a service operating within an Azure Virtual Network (VNet) or from allowed public IP addresses.

已完成的排查操作

  • 源数据集测试连接成功,可正常预览数据
  • 已为存储账户配置Storage Blob Data Contributor和Storage Blob Data Reader角色

下一步排查与解决步骤

  • 检查文件夹层级权限:ADLS Gen2对路径遍历有严格权限要求,需在存储资源管理器中给使用的MI/SP分别授予container、firstDir、SecondDir这三层文件夹的**执行(Execute)权限,同时给目标JSON文件授予读取(Read)**权限。
  • 验证角色生效范围:确认IAM角色是分配到存储账户层级,而非仅容器或文件夹层级。若之前仅分配到子资源,建议在存储账户的IAM界面重新分配角色,确保权限范围覆盖整个存储账户。
  • 排查存储账户防火墙:如果存储账户开启了防火墙规则,需确认ADF的访问路径被允许。可临时关闭防火墙测试,若问题解决,再将ADF托管标识加入VNet允许列表,或添加ADF的公共IP至存储账户的允许IP范围。
  • 确认集成运行环境配置:若使用自托管集成运行时,需确保运行时所在机器的IP已被存储账户防火墙允许;若使用Azure托管集成运行时且启用了VNet集成,需配置存储账户的服务端点或私有链接。
  • 核对链接服务身份配置:确认链接服务使用的MI/SP与之前作为接收器时完全一致,无身份误选情况。可重新保存链接服务后,再次运行数据流测试。
  • 等待权限同步:Azure RBAC权限生效通常需要5-15分钟,即使测试连接成功,数据流运行可能未同步到最新权限,等待一段时间后重试。

内容的提问来源于stack exchange,提问作者lem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 12:22:44