Power BI API的GenerateTokenInGroup与GenerateTokenForCreateInGroup返回Forbidden错误
Power BI GenerateToken API 403 Forbidden 问题
近期调用Power BI的GenerateTokenInGroup和GenerateTokenForCreateInGroup API时,返回错误:Operation returned an invalid status code 'Forbidden'。该功能上周可正常运行,且相同配置下GetReportsInGroup API能成功执行。
相关代码
public class Secrets { private static string authorityUrl = "https://login.microsoftonline.com/organizations/"; private static string resourceUrl = "https://analysis.windows.net/powerbi/api"; public static string apiUrl = "https://api.powerbi.com/"; private static string ClientID = ""; // The Azure AD App - Application ID/Client ID private static string ClientSecret = ""; // The Azure AD App - Client Secret private static string TenantId = ""; // The Azure AD Tenant Id public static Guid groupId = Guid.Parse("");//Power BI Workspace ID private static ClientCredential credential = null; private static AuthenticationResult authenticationResult = null; public static TokenCredentials tokenCredentials = null; public static Task Authorize() { return Task.Run(async () => { credential = new ClientCredential(ClientID, ClientSecret); authenticationResult = null; tokenCredentials = null; var tenantSpecificURL = authorityUrl.Replace("organizations", Secrets.TenantId); var authenticationContext = new AuthenticationContext(tenantSpecificURL); authenticationResult = await authenticationContext.AcquireTokenAsync(resourceUrl, credential); if (authenticationResult != null) { tokenCredentials = new TokenCredentials(authenticationResult.AccessToken, "Bearer"); } }); } } public class PowerBIController : ApiController { private PowerBIClient PowerBIClient { get; set; } public PowerBIController() { Secrets.Authorize().Wait(); PowerBIClient = new(new Uri(Secrets.apiUrl), Secrets.tokenCredentials); } [HttpGet] public object GetReportsInGroup() { return PowerBIClient.Reports.GetReportsInGroup(Secrets.groupId).Value; } [HttpGet] public object GenerateTokenInGroup(Guid reportId, Guid datasetId) { return PowerBIClient.Reports.GenerateTokenInGroup(Secrets.groupId, reportId, new GenerateTokenRequest(accessLevel: "View", datasetId: datasetId.ToString())); } [HttpGet] public object GenerateTokenForCreateInGroup(Guid datasetId) { return PowerBIClient.Reports.GenerateTokenForCreateInGroup(Secrets.groupId, new GenerateTokenRequest(accessLevel: "Create", datasetId: datasetId.ToString(), allowSaveAs: true)); } }
已配置权限说明
已配置Power BI相关API权限,包含报表、数据集的读写类权限。
排查解决方案
- 权限差异验证:
GetReportsInGroup仅需报表读取权限,但生成嵌入令牌的API要求更高:GenerateTokenInGroup需Report.ReadWrite.All应用权限,或Report.Read.All+服务主体为工作空间成员/管理员GenerateTokenForCreateInGroup需Report.Create应用权限,且服务主体必须是目标工作空间的成员或管理员
- 服务主体工作空间权限:确认Azure AD应用(服务主体)已添加到目标Power BI工作空间,角色设置为成员或管理员(访客角色无法生成令牌)
- 管理员同意检查:确保Azure AD应用的API权限已获得管理员同意,且添加的是应用权限而非仅委派权限(服务主体模式下需应用权限)
- 令牌内容验证:解码获取到的access token,检查
roles字段是否包含所需权限(如Report.ReadWrite.All、Report.Create) - SDK版本兼容:尝试升级Power BI .NET SDK到最新稳定版,避免版本不兼容导致的权限校验问题
- 容量状态检查:若工作空间使用Premium容量,确认容量运行正常;共享容量下部分创建类令牌操作可能受限制
内容的提问来源于stack exchange,提问作者Hassan Abbas
相关产品推荐
相关产品推荐

