Power BI Troubleshooting
This page lists common issues when connecting Sifflet to Power BI. Error messages appear in the connection test report and in the logs of the source details (click the source name in Integrations > Sources).
Authentication
The Secret Is Rejected as Invalid
Symptom:
Invalid secret provided. Please ensure the secret is the secret value, not the secret ID.Cause: the credential doesn't contain the client secret value. A common mistake is to copy the Secret ID column instead of the Value column in Microsoft Entra ID.
Fix:
- Create a new client secret and copy its Value, as described in Step 1 (Microsoft Entra ID only shows the value once).
- Update the credential in Integrations > Credentials with this value.
- Run the source again.
The Secret Has Expired
Symptom:
Expired secret provided. Please use another, non-expired secret.Cause: the client secret has reached the expiry date chosen when it was created.
Fix:
- In Microsoft Entra ID, open the app and create a new client secret, as described in Step 1.
- Update the credential in Integrations > Credentials with the new secret value.
- Run the source again.
The Tenant ID or Client ID Is Rejected
Symptom:
Invalid Tenant ID provided.or
Invalid Client ID provided.Cause: the Azure AD tenant id or Azure AD client id field of the source doesn't match the app registration.
Fix:
- Copy the Directory (tenant) ID and Application (client) ID from the app's Overview page in Microsoft Entra ID.
- Update the source fields, as described in Step 2.
Permissions
"API Is Not Accessible for Application"
Symptom: the refresh fails with an error like:
Error encountered when trying to pull Power BI remote state, cause = Error encountered when trying to get scan response for workspace id 403 Forbidden: "{"Message":"API is not accessible for application"}", scan id {1}Cause: Power BI doesn't allow the service principal to call its APIs: a tenant setting isn't enabled, or the service principal isn't in the security group the setting applies to.
Fix:
- Check that all the tenant settings listed in Enable the Power BI Tenant Settings are enabled and apply to the security group that contains the service principal.
- Check that the app has no Power BI API permission that requires admin consent, as described in Register the App and Create a Client Secret.
- Wait up to 15 minutes for Power BI to apply the changes, then run the source again.
Too Many Requests
Symptom:
Too many requests have been made against Power Bi.Cause: the Power BI admin API limits of your tenant are reached. These limits are shared with your other tools that use the Power BI admin APIs.
Fix:
- Run the source again later.
- If the error persists, reduce the refresh frequency of the source (see Integrations Management), or schedule it at a time when your other tools don't call the admin APIs.
Lineage
Lineage to the Data Warehouse Is Incomplete
Symptom: some Power BI semantic model tables have no upstream warehouse table in the lineage.
Cause: either the semantic model's source expressions use parameters and Sifflet can't read them, because the service principal doesn't have the Member role on the workspace; or the warehouse table isn't cataloged in Sifflet, or comes from an unsupported platform.
Fix:
- Add the service principal to the workspace with the Member role, as described in Optional: Add the Service Principal to Your Workspaces.
- Check that the warehouse tables are cataloged in Sifflet through their own source, and that the platform is supported (see Lineage).
- Run the source again.
Updated about 3 hours ago

