Azure Data Factory Web活动中不使用MSI从密钥保管库获取凭证的方法咨询
How to Retrieve Credentials from Azure Key Vault in ADF (Without MSI) for REST API Authentication
Hey there! I get that switching from hardcoded values to Key Vault can feel tricky at first, especially when avoiding MSI. Let's break this down step by step so you can get your Web Activity authenticated properly:
1. First, Set Up Your Key Vault Secrets
- Head to your Azure Key Vault and create two separate secrets: one for your
userId(e.g., name itapi-auth-userid) and one for yourpassword(e.g.,api-auth-password). Make sure to store the exact values you were previously hardcoding.
2. Create a Service Principal for ADF <-> Key Vault Access
Since we're skipping MSI, we'll use a service principal to let ADF access Key Vault:
- Go to Azure Active Directory → App registrations → New registration. Give it a name (like
ADF-KeyVault-Access) and register it. - Once created, note down the Client ID (under Overview) and generate a Client Secret (under Certificates & secrets → New client secret). Save this secret value immediately—you won't see it again!
- Now go back to your Key Vault → Access policies → Add access policy. Select the
Getpermission under Secrets, then search for and select your new service principal. Save the policy.
3. Link Key Vault to ADF Using the Service Principal
- In your Azure Data Factory, go to Manage → Linked services → New. Search for "Azure Key Vault" and select it.
- Fill in your Key Vault details (subscription, vault name). Under Authentication type, choose Service Principal.
- Enter the Client ID, Client Secret, and Tenant ID (from your Azure AD tenant) that you noted earlier. Test the connection to make sure it works, then save the linked service.
4. Use Lookup Activities to Fetch Secrets in Your Pipeline
You'll need two Lookup activities (one per secret) to pull the values from Key Vault:
- Add a new Lookup activity to your pipeline (name it
Fetch_UserId). For the Source, select your Key Vault linked service. In the Secret name field, enter the exact name of your userId secret (e.g.,api-auth-userid). - Repeat this for a second Lookup activity (
Fetch_Password), targeting your password secret. - Make sure these Lookup activities run before your Web Activity—you can set up dependencies by dragging a line from each Lookup to the Web Activity.
5. Configure Your Web Activity's POST Body
Now plug the fetched secrets into your Web Activity's request body:
- Open your Web Activity, set the Method to
POST, and enter your authentication API URL. - Under Body, switch to dynamic content mode and paste in your JSON structure, replacing the hardcoded values with the Lookup outputs:
{ "userId": "@activity('Fetch_UserId').output.firstRow.value", "password": "@activity('Fetch_Password').output.firstRow.value" } - Don't forget to set the correct
Content-Typeheader (usuallyapplication/json) in the Web Activity's Headers section.
Quick Notes to Avoid Pitfalls
- Minimize Permissions: Ensure your service principal only has the
Getpermission on Key Vault secrets—no need for broader access. - Secret Rotation: Remember to rotate your service principal's client secret periodically, and update the linked service in ADF when you do.
- Debugging: If things don't work, check the Lookup activity outputs first to confirm the secrets are being fetched correctly. Then inspect the Web Activity's request body in the pipeline run details.
That's it! This setup will keep your credentials secure in Key Vault while letting your ADF pipeline authenticate to your REST API without hardcoding or using MSI.
内容的提问来源于stack exchange,提问作者CSharpDev
相关产品推荐
相关产品推荐

