如何通过REST接口使用ADAL完成身份验证以调用Power BI API
Absolutely! You can absolutely handle ADAL authentication for Power BI APIs using raw HTTP requests—no SDKs or DLLs required. ADAL is just a wrapper around OAuth 2.0 flows, so we can directly use the underlying REST endpoints to get the access token you need. Let me walk you through the two most common flows for server-side/script-based access:
Prerequisites First
Before you start, make sure you have these details handy:
- Your Azure AD Tenant ID (found in Azure Portal > Azure Active Directory > Overview)
- A registered Azure AD app's Client ID (Application ID)
- Either a Client Secret (for service principal access) or a user's username/password (for resource owner flow, note: this has limitations)
- Power BI's resource ID:
https://analysis.windows.net/powerbi/api(fixed for all Power BI API calls)
Flow 1: Service Principal (Client Credentials Flow)
This is the recommended approach for background services or scripts that don't need to act as a specific user. It uses your app's own credentials to authenticate.
Step 1: Request the Access Token
Send a POST request to the Azure AD token endpoint:
POST https://login.microsoftonline.com/{your-tenant-id}/oauth2/token Content-Type: application/x-www-form-urlencoded
The request body (form-encoded) should include these parameters:
grant_type=client_credentialsclient_id={your-client-id}client_secret={your-client-secret}resource=https://analysis.windows.net/powerbi/api
Example Request (cURL)
curl -X POST "https://login.microsoftonline.com/your-tenant-id/oauth2/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=client_credentials&client_id=your-client-id&client_secret=your-client-secret&resource=https://analysis.windows.net/powerbi/api"
Step 2: Use the Token
The response will include an access_token field. Use this in the Authorization header for all Power BI API calls:
GET https://api.powerbi.com/v1.0/myorg/groups Authorization: Bearer {your-access-token}
Flow 2: Resource Owner Password Credentials (ROPC) Flow
This flow lets you authenticate as a specific user using their username and password. Important note: Microsoft discourages this for production use because it exposes user credentials, and it won't work for users with MFA enabled.
Step 1: Request the Access Token
Send a POST request to the same token endpoint:
POST https://login.microsoftonline.com/{your-tenant-id}/oauth2/token Content-Type: application/x-www-form-urlencoded
Request body parameters:
grant_type=passwordclient_id={your-client-id}username={user-email@domain.com}password={user-password}resource=https://analysis.windows.net/powerbi/apiscope=https://analysis.windows.net/powerbi/api/.default(optional but recommended)
Example Request (cURL)
curl -X POST "https://login.microsoftonline.com/your-tenant-id/oauth2/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=password&client_id=your-client-id&username=user@domain.com&password=user-password&resource=https://analysis.windows.net/powerbi/api&scope=https://analysis.windows.net/powerbi/api/.default"
Step 2: Use & Refresh the Token
The response will include access_token (use immediately) and refresh_token (use to get a new access token when the old one expires, after ~1 hour). To refresh, send a POST with grant_type=refresh_token and the refresh token value.
Key Notes & Gotchas
- Permissions: Make sure your Azure AD app has been granted the necessary Power BI API permissions (e.g.,
Workspace.Read.All,Dataset.ReadWrite.All) in the Azure Portal, and that an admin has consented to these permissions. - Token Expiry: Access tokens are valid for ~1 hour. For service principal flow, you'll need to re-request a token when it expires (no refresh token is issued here).
- Security: Never hardcode client secrets or user passwords in your code. Use environment variables, secret managers, or secure vaults instead.
- MFA Limitation: ROPC flow will fail for users with multi-factor authentication enabled—stick to service principal flow if MFA is used in your organization.
内容的提问来源于stack exchange,提问作者webworm

