You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Data Factory Web活动中不使用MSI从密钥保管库获取凭证的方法咨询

How to Retrieve Credentials from Azure Key Vault in ADF (Without MSI) for REST API Authentication

Hey there! I get that switching from hardcoded values to Key Vault can feel tricky at first, especially when avoiding MSI. Let's break this down step by step so you can get your Web Activity authenticated properly:

1. First, Set Up Your Key Vault Secrets

  • Head to your Azure Key Vault and create two separate secrets: one for your userId (e.g., name it api-auth-userid) and one for your password (e.g., api-auth-password). Make sure to store the exact values you were previously hardcoding.

2. Create a Service Principal for ADF <-> Key Vault Access

Since we're skipping MSI, we'll use a service principal to let ADF access Key Vault:

  • Go to Azure Active Directory → App registrations → New registration. Give it a name (like ADF-KeyVault-Access) and register it.
  • Once created, note down the Client ID (under Overview) and generate a Client Secret (under Certificates & secrets → New client secret). Save this secret value immediately—you won't see it again!
  • Now go back to your Key Vault → Access policies → Add access policy. Select the Get permission under Secrets, then search for and select your new service principal. Save the policy.
  • In your Azure Data Factory, go to Manage → Linked services → New. Search for "Azure Key Vault" and select it.
  • Fill in your Key Vault details (subscription, vault name). Under Authentication type, choose Service Principal.
  • Enter the Client ID, Client Secret, and Tenant ID (from your Azure AD tenant) that you noted earlier. Test the connection to make sure it works, then save the linked service.

4. Use Lookup Activities to Fetch Secrets in Your Pipeline

You'll need two Lookup activities (one per secret) to pull the values from Key Vault:

  • Add a new Lookup activity to your pipeline (name it Fetch_UserId). For the Source, select your Key Vault linked service. In the Secret name field, enter the exact name of your userId secret (e.g., api-auth-userid).
  • Repeat this for a second Lookup activity (Fetch_Password), targeting your password secret.
  • Make sure these Lookup activities run before your Web Activity—you can set up dependencies by dragging a line from each Lookup to the Web Activity.

5. Configure Your Web Activity's POST Body

Now plug the fetched secrets into your Web Activity's request body:

  • Open your Web Activity, set the Method to POST, and enter your authentication API URL.
  • Under Body, switch to dynamic content mode and paste in your JSON structure, replacing the hardcoded values with the Lookup outputs:
    {
      "userId": "@activity('Fetch_UserId').output.firstRow.value",
      "password": "@activity('Fetch_Password').output.firstRow.value"
    }
    
  • Don't forget to set the correct Content-Type header (usually application/json) in the Web Activity's Headers section.

Quick Notes to Avoid Pitfalls

  • Minimize Permissions: Ensure your service principal only has the Get permission on Key Vault secrets—no need for broader access.
  • Secret Rotation: Remember to rotate your service principal's client secret periodically, and update the linked service in ADF when you do.
  • Debugging: If things don't work, check the Lookup activity outputs first to confirm the secrets are being fetched correctly. Then inspect the Web Activity's request body in the pipeline run details.

That's it! This setup will keep your credentials secure in Key Vault while letting your ADF pipeline authenticate to your REST API without hardcoding or using MSI.

内容的提问来源于stack exchange,提问作者CSharpDev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 10:32:55