You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为本地SSAS生成Power BI嵌入令牌时遇Forbidden错误求助

本地SSAS连接的Power BI嵌入令牌生成问题

我正在尝试为本地SSAS(SQL Server Analysis Services)连接生成Power BI嵌入令牌,最终目的是传递安全凭据,从而在Power BI中利用SSAS的角色安全机制。但作为嵌入开发新手,第一步生成初始嵌入令牌就遇到了困难。

我已通过以下代码成功为带RLS(行级别安全)的常规Power BI数据集生成嵌入令牌:

private static bool useEmbedToken = true;
private static bool useRLS = true;

private static string authorityUrl = "https://login.microsoftonline.com/organizations/";
private static string resourceUrl = "https://analysis.windows.net/powerbi/api";
private static string apiUrl = "https://api.powerbi.com/";

private static string tenantId = "TENANT";  //Working
private static Guid groupId = Guid.Parse("GROUP");

private static Guid reportId = Guid.Parse("REPORT");//
private static Guid datasetId = Guid.Parse("DATASET"); //


// **** Update the Client ID and Secret within Secrets.cs ****

private static ClientCredential credential = null;
private static AuthenticationResult authenticationResult = null;
private static TokenCredentials tokenCredentials = null;

static void Main(string[] args)
{

    //try
    {
        // Create a user password cradentials.
        credential = new ClientCredential(Secrets.ClientID, Secrets.ClientSecret);

        // Authenticate using created credentials
        Authorize().Wait();

        using (var client = new PowerBIClient(new Uri(apiUrl), tokenCredentials))
        {

            #region Embed Token
            EmbedToken embedToken = null;


            if (useEmbedToken && !useRLS)
            {
                

            }
            else if (useEmbedToken && useRLS)
            {
                // **** With RLS ****

                

                var rls = new EffectiveIdentity(username: "USER@COMPANY.com", new List<string> { datasetId.ToString() });

                var rolesList = new List<string>();
                rolesList.Add("Role");
                rls.Roles = rolesList;

                embedToken = client.Reports.GenerateTokenInGroup(groupId, reportId,
                    new GenerateTokenRequest(accessLevel: "View", datasetId: datasetId.ToString(), rls));

                //var generateTokenRequestParameters = new GenerateTokenRequestV2(
                //    datasets:  datasetId.ToString(),
                //    reports: reportId,
                //    targetWorkspaces: groupId,
                //    allowEdit: true,
                //    accessLevel: "view";
            }

适配本地SSAS场景时,收到Forbidden错误,具体错误信息如下:

Microsoft.Rest.HttpOperationException
  HResult=0x80131500
  Message=Operation returned an invalid status code 'Forbidden'
  Source=Microsoft.PowerBI.Api
  StackTrace:
   at Microsoft.PowerBI.Api.ReportsOperations.<GenerateTokenInGroupWithHttpMessagesAsync>d__34.MoveNext()
   at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)
   at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)
   at Microsoft.PowerBI.Api.ReportsOperationsExtensions.<GenerateTokenInGroupAsync>d__95.MoveNext()
   at System.Runtime.CompilerServices.TaskAwaiter.ThrowForNonSuccess(Task task)
   at System.Runtime.CompilerServices.TaskAwaiter.HandleNonSuccessAndDebuggerNotification(Task task)
   at Microsoft.PowerBI.Api.ReportsOperationsExtensions.GenerateTokenInGroup(IReportsOperations operations, Guid groupId, Guid reportId, GenerateTokenRequest requestParameters)
   at EmbedAPISample.Program.Main(String[] args) in C:\Users\USER\OneDrive\Documents\Projects\Power BI\Embed-API-Sample-master\Embed-API-Sample-master\EmbedAPISample\Program.cs:line 111

已完成的配置操作:

  • 创建Azure AD应用注册并授予所有委派权限
  • 将应用主体名称添加到工作区和所使用的网关中
  • 配置有效用户名映射:将user@Company.com映射为User@Staging.com(SSAS角色使用Staging域)
  • 同一代码在同一工作区的非SSAS数据集上可正常运行

内容的提问来源于stack exchange,提问作者NutellaKing

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 09:27:47