An Azure service that provides an event-driven serverless compute platform.
Hi @Martin Kafka ,
Thank you for reaching out to Microsoft Q & A !
Based on the documented Fabric Apps capabilities, your understanding of the authentication limitation is reasonable.
Fabric Apps provides static frontend hosting and managed Fabric services, including authentication, database, and generated GraphQL APIs. Deployed applications use Fabric SSO (Microsoft Entra ID) for authentication.
For the Data Agent scenario, Microsoft documents service principal authentication using the client credentials flow. Since the service principal credentials are used to acquire the Microsoft Entra access token, they should not be placed in the published React SPA. The practical architecture is to keep the credential and token acquisition in a trusted server-side component and have the React SPA call that backend.
Regarding Fabric App Functions, I couldn't find public Microsoft documentation that provides a committed availability date or roadmap timeline for this capability. Since your deployment is explicitly returning "Functions not supported", I would recommend designing the current solution around the capabilities available today rather than relying on a particular future availability date.
For your requirement, using an external backend such as Azure Functions or another trusted server-side service is therefore the appropriate approach rather than exposing service principal credentials in the Fabric-hosted SPA.
References:
- Use service principal authentication with Fabric data agent https://learn.microsoft.com/en-us/fabric/data-science/data-agent-service-principal
- What is Fabric Apps (Preview)? https://learn.microsoft.com/en-us/fabric/apps/overview
Please "Upvote the Answer" if this information helped you. This will help us and others in the community as well.