Power BI Connector for CSV

Build 26.0.9770

Creating a Custom Azure AD Application

Creating a Custom AzureAD Application

Connecting to Azure Data Lake Storage via a Web application requires the creation of a custom AzureAD application.

If you are connecting via a Desktop application or a Headless machine, you can use the embedded OAuth Application Credentials with CData branding that ship with CData Power BI Connector for CSV. However, you can also connect using a custom AzureAD application. Custom AzureAD applications may be useful if you want to:

  • control branding of the Authentication Dialog;
  • control the redirect URI that the application redirects the user to after the user authenticates; or
  • customize the permissions that you are requesting from the user.

How to Authenticate Using a Custom AzureAD Application

To authenticate using a custom AzureAD application, you register a single custom application in the AzureAD portal. You can then use this custom application in either of the following ways:

  • To authenticate as a signed-in user (user-based authentication), use the AzureAD authentication scheme (AuthScheme=AzureAD).
  • To authenticate as the application itself, without a user, (application-based authentication), you must create a service principal from the same registration and use the AzureServicePrincipal authentication scheme (AuthScheme=AzureServicePrincipal.

Both of these types of authentication are OAuth-based.

Before You Begin

The custom applications you create for use with Azure Data Lake Storage must be assigned specific roles.

Assigning Azure Roles

The individual assigning Azure roles must have Microsoft.Authorization/roleAssignments/write permission, which is included in the following roles:

  • Role Based Access Control Administrator
  • User Access Administrator

Azure AD Authentication Roles

The delegating user must be assigned these roles:

  • Storage Blob Data Owner
  • Storage Blob Data Contributor

Azure Service Principal Authentication Roles

The custom Service Principal application must be assigned these roles:

  • Storage Blob Data Owner
  • Storage Blob Data Contributor

Checking Current Access

To check access for users or custom applications, log in to the Azure Portal and navigate to Subscriptions > Access control (IAM) > Check access.

In the Check Access screen, search by the name of the user or application. The portal displays that user or application's current role assignments.

Creating a Custom AzureAD Application

You can use a custom AzureAD application by itself, to authenticate as a signed-in user, or use it with an Azure Service Principal to authenticate as the application itself.

To create the custom AzureAD application and obtain your custom application's OAuthClientId and OAuthClientSecret, do the following:

  1. Log in to https://portal.azure.com.
  2. In the left-hand navigation pane, select All services. Filter and select App registrations.
  3. Click New registrations.
  4. Enter an application name and select the desired tenant setup.
    When creating a custom AzureAD application in Azure Active Directory, you can define whether the application is single- or multi-tenant. If you select the default option, "Accounts in this organizational directory only", when establishing a connection with CSV you must set the AzureTenant connection property to the Id of the Azure AD Tenant. Otherwise, the authentication attempt fails with an error.
    If your application is for private use only, "Accounts in this organization directory only" should be sufficient. Otherwise, if you want to distribute your application, choose one of the multi-tenant options.
  5. Either set the redirect url to http://localhost:33333, the connector's default, or specify a different port and set CallbackURL to the exact reply URL you defined.
  6. Click Register to register the new application. This opens an application management screen.
  7. Note the value in Application (client) ID as the OAuthClientId and the Directory (tenant) ID as the AzureTenant.
  8. Navigate to "Certificates & Secrets" and define the application authentication type. There are two types of authentication available: using a client secret or a certificate. The recommended authentication method is using a certificate.
    • Option 1: Upload a certificate: In "Certificates & Secrets", select Upload certificate and the certificate to upload from your local machine.
    • Option 2: Create a new application secret: In "Certificates & Secrets", select New Client Secret for the application and specify its duration. After saving the client secret, the key value is displayed. Copy this value as it is displayed only once. You will need it as the OAuthClientSecret.
  9. Select API Permissions > Add. If your application connects without a user context, select Application Permissions. If your application authenticates on behalf of a signed-in user, choose Delegated permissions.
  10. Save your changes.
  11. If you have selected to use permissions that require admin consent (such as the Application Permissions), you can grant them from the current tenant on the API Permissions page. Otherwise, follow the steps under "Admin Consent".

Creating an AzureAD Service Principal Application

When authenticating using an Azure Service Principal, you must create both a custom AzureAD application and an Azure Service Principal that can access the necessary resources.

After you have created the custom AzureAD application, follow these steps to create the Azure Service Principal:

  1. Log in to https://portal.azure.com.
  2. In the left-hand navigation pane, select All services. Filter and select App registrations.
  3. Click New registrations.
  4. Enter an app name and select Any Azure AD Directory - Multi Tenant. Then set the redirect url to http://localhost:33333, the connector's default.
  5. After creating the application, copy the Application (client) Id value displayed in the "Overview" section. This value is used as the OAuthClientId
  6. Define the app authentication type by going to the "Certificates & Secrets" section. There are two types of authentication available: using a client secret and using a certificate. The recommended authentication method is via a certificate.
    • Option 1: Upload a certificate: In "Certificates & Secrets", select Upload certificate and the certificate to upload from your local machine.
    • Option 2: Create a new application secret: In "Certificates & Secrets", select New Client Secret for the application and specify its duration. After saving the client secret, the key value is displayed. Copy this value as it is displayed only once. You will use it as the OAuthClientSecret.
  7. On the Authentication tab, make sure to select Access tokens (used for implicit flows).

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770