1. Create the app registration
In Entra ID → App registrations → New registration, register an app with any name, for example fabriscope. It needs no redirect URI. Under Certificates & secrets, create a client secret and copy its value; you paste it once, under Settings → Connection.
Note the Application (client) ID and the Directory (tenant) ID from the app's overview.
2. Microsoft Graph permissions (optional)
Only Report Audience uses Microsoft Graph, for two things: Pro and Premium Per User licences, and the people inside an Entra group that holds access to a report.
| API | Permission (application) | Used for |
|---|---|---|
| Microsoft Graph | User.Read.All, Organization.Read.All | Licences: who holds a Pro or PPU seat |
| Microsoft Graph | GroupMember.Read.All | The people inside a group, nested groups included |
Grant admin consent. Without them, the Licences page says it is unavailable and a group grant shows as the group rather than its people.
3. Allow the read-only admin APIs
In the Fabric admin portal → Tenant settings, create a security group (for example sg-fabriscope) containing the service principal, and enable Service principals can use read-only admin APIs for that group. This is required: both products read the inventory, access and audit log through it.
The two Enhance admin API responses with detailed metadata settings are not needed. Tenant settings take up to 15 minutes to apply.
4. Contributor on the workspaces to document
For the Data Catalog, add the service principal as Contributor on each workspace to document: Workspace → Manage access → Add people or groups. Include the workspaces your code writes into, not only those that hold the code. Report Audience needs no workspace role at all.
5. Connect
Under Settings → Connection, enter the directory (tenant) ID, the application (client) ID and the secret value, then choose Connect. The secret is encrypted and never shown again; enter a new one there to rotate it.
The page then checks each part live:
| Check | Needed for | If it fails |
|---|---|---|
| Read-only admin APIs | Both products — required | Step 3 has not applied yet, or the principal is not in the group |
| Fabric REST API | Data Catalog: items and code | Step 4: the principal has no role on the workspaces |
| OneLake | Data Catalog: tables and the Delta log | Step 4: Contributor on the workspace |
| Microsoft Graph | Report Audience: licences, group members | Step 2 — optional |
Changed a setting? Use Re-validate; Microsoft can take 15–60 minutes to apply a change.