REST APIs, service principals and a tenant inventory
ApiGroups ApiDatasets ApiReports ApiRefreshes ApiViews- Why it matters
- You can't govern what you can't see. A scripted inventory answers "what do we have, who owns it, is it used, is it healthy" in minutes, every week, without asking anyone.
- Typical production failure
- An inventory script authenticates with a developer's personal account; when they leave, it stops, and nobody notices for a month.
- When to use it
- A service principal (app registration) in a security group allowed by the tenant settings, least-privilege workspace access, secrets outside the code, and the Power BI or Fabric REST APIs (admin APIs or the scanner API for tenant-wide views).
- When not to
- Hard-coded secrets, personal credentials, and admin APIs when workspace-level permissions would do.
Assignments
Build a workspace inventory from API responses
Write a script that turns the API responses into one inventory table: workspace, semantic model, owner, reports, last refresh status, endorsement, and whether each report was viewed in the last 90 days.
- Read the five JSON files (they have the same shape as the real API responses).
- One row per report, with its model and workspace.
- Summary counts for the governance review.
- Structure it so the file-reading part can be swapped for real API calls.
Set up a service principal properly
Write the setup checklist your team will follow to give the inventory script its own identity instead of a person's account.
- App registration and client secret or certificate, and where the secret lives.
- Security group, and the tenant settings that must allow it.
- Workspace access (which role, which workspaces) or read-only admin API access, and why.
- Token request: authority, scope and flow.
The secret in the repository
Sam pushed the inventory script to the team's GitHub repository with the client secret in a variable. The repository is internal, but 40 people can read it. What do you do, in order?
- Containment first.
- Clean-up of the repository and its history.
- Prevention.
Interview questions
- What is a service principal and why use one for automation?
- Which tenant settings control service principals in Fabric?
- Admin APIs vs regular APIs?
- How would you inventory every workspace in a large tenant?
Assessment
Your inventory script should authenticate with:
- The BI lead's account
- A service principal in an allowed security group, secret in a key vault
- A shared password in the script
- Anonymous access
To read metadata for every workspace in the tenant efficiently, use:
- GET /groups for each user
- The admin scanner API (getInfo, scanStatus, scanResult)
- Export to Excel from the portal
- XMLA on each model
Extend your inventory with each model's data sources and gateway (datasources endpoint, or the scanner API's datasourceInstances).
GET /groups/{groupId}/datasets/{datasetId}/datasources; group sources by server to see which models depend on which systems.