You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Power BI API的GenerateTokenInGroup与GenerateTokenForCreateInGroup返回Forbidden错误

Power BI GenerateToken API 403 Forbidden 问题

近期调用Power BI的GenerateTokenInGroup和GenerateTokenForCreateInGroup API时,返回错误:Operation returned an invalid status code 'Forbidden'。该功能上周可正常运行,且相同配置下GetReportsInGroup API能成功执行。

相关代码

public class Secrets
{
    private static string authorityUrl = "https://login.microsoftonline.com/organizations/";
    private static string resourceUrl = "https://analysis.windows.net/powerbi/api";
    public static string apiUrl = "https://api.powerbi.com/";
    private static string ClientID = ""; // The Azure AD App - Application ID/Client ID
    private static string ClientSecret = ""; // The Azure AD App - Client Secret
    private static string TenantId = ""; // The Azure AD Tenant Id
    public static Guid groupId = Guid.Parse("");//Power BI Workspace ID
    private static ClientCredential credential = null;
    private static AuthenticationResult authenticationResult = null;
    public static TokenCredentials tokenCredentials = null;
    public static Task Authorize()
    {
        return Task.Run(async () =>
        {
            credential = new ClientCredential(ClientID, ClientSecret);
            authenticationResult = null;
            tokenCredentials = null;
            var tenantSpecificURL = authorityUrl.Replace("organizations", Secrets.TenantId);
            var authenticationContext = new AuthenticationContext(tenantSpecificURL);
            authenticationResult = await authenticationContext.AcquireTokenAsync(resourceUrl, credential);
            if (authenticationResult != null)
            {
                tokenCredentials = new TokenCredentials(authenticationResult.AccessToken, "Bearer");
            }
        });
    }
}
public class PowerBIController : ApiController
{
    private PowerBIClient PowerBIClient { get; set; }
    public PowerBIController()
    {
        Secrets.Authorize().Wait();
        PowerBIClient = new(new Uri(Secrets.apiUrl), Secrets.tokenCredentials);
    }
    [HttpGet]
    public object GetReportsInGroup()
    {
        return PowerBIClient.Reports.GetReportsInGroup(Secrets.groupId).Value;
    }
    [HttpGet]
    public object GenerateTokenInGroup(Guid reportId, Guid datasetId)
    {
        return PowerBIClient.Reports.GenerateTokenInGroup(Secrets.groupId, reportId, new GenerateTokenRequest(accessLevel: "View", datasetId: datasetId.ToString()));
    }
    [HttpGet]
    public object GenerateTokenForCreateInGroup(Guid datasetId)
    {
        return PowerBIClient.Reports.GenerateTokenForCreateInGroup(Secrets.groupId, new GenerateTokenRequest(accessLevel: "Create", datasetId: datasetId.ToString(), allowSaveAs: true));
    }
}

已配置权限说明

已配置Power BI相关API权限,包含报表、数据集的读写类权限。

排查解决方案

  • 权限差异验证:GetReportsInGroup仅需报表读取权限,但生成嵌入令牌的API要求更高:
    • GenerateTokenInGroup需Report.ReadWrite.All应用权限,或Report.Read.All+服务主体为工作空间成员/管理员
    • GenerateTokenForCreateInGroup需Report.Create应用权限,且服务主体必须是目标工作空间的成员或管理员
  • 服务主体工作空间权限:确认Azure AD应用(服务主体)已添加到目标Power BI工作空间,角色设置为成员或管理员(访客角色无法生成令牌)
  • 管理员同意检查:确保Azure AD应用的API权限已获得管理员同意,且添加的是应用权限而非仅委派权限(服务主体模式下需应用权限)
  • 令牌内容验证:解码获取到的access token,检查roles字段是否包含所需权限(如Report.ReadWrite.All、Report.Create)
  • SDK版本兼容:尝试升级Power BI .NET SDK到最新稳定版,避免版本不兼容导致的权限校验问题
  • 容量状态检查:若工作空间使用Premium容量,确认容量运行正常;共享容量下部分创建类令牌操作可能受限制

内容的提问来源于stack exchange,提问作者Hassan Abbas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 21:43:12