You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[Bug] pa app add data-source / pa connection list-datasets fails with AuthenticationError for shared_sharepointonline, even on a brand-new connection #459
Cloud: commercial (not GCC/GCC High/DoD) — confirmed via make.powerapps.com
OS/shell: Windows 11, PowerShell
Auth: interactive user (pa auth login), not a service principal
Symptom
Adding a SharePoint Online tabular data source fails with a 403 directly from the connector API Management layer:
HTTP error status: 403 for GET https://<env>.01.common.usa002.azure-apihub.net/apim/sharepointonline/<connection-id>/$metadata.json/datasets/<encoded-site-url>/tables/<encoded-table-name>
Response body:
{
"Message": "Missing Authorization header for a privileged call on connection.",
"Source": "product policy"
}
The same failure reproduces one level down, using pa connection list-datasets directly (no table/dataset involved at all):
pa connection list-datasets --connector shared_sharepointonline --connection-id <connection-id>
Failed to get datasets for connection '<connection-id>' and connector 'shared_sharepointonline': {"exitCode":3,"remediation":"Run `pa auth login` to sign in, or verify you have access to this environment.","name":"AuthenticationError"}
What I've ruled out
Not a stale/broken connection: created a brand-new shared_sharepointonline connection via pa connection create --connector shared_sharepointonline (fresh interactive OAuth consent, browser sign-in completed successfully). The new connection fails identically with the same AuthenticationError.
Not connection ownership: pa connection list shows both connections owned by the currently authenticated user.
Not environment mismatch: both connections appear under pa connection list in the active environment, matching environmentId in power.config.json.
Not a service-principal auth issue: pa auth status shows an interactive user account, not an app registration.
Not table-name encoding: reproduces even at the list-datasets step, before any table/dataset value is involved.
Not GCC-specific (ruling out the class of bug in [Bug] AADSTS65002 When Adding SharePoint Data Source via Power Apps CLI #348 / AADSTS65002): confirmed via make.powerapps.com this is a standard commercial tenant, and the error text/code here is a different one ("Missing Authorization header for a privileged call on connection" / product policy, not AADSTS65002).
Not a broader auth/environment breakdown: pa app add data-source --connector dataverse --table account succeeds cleanly in the same environment, same auth session, same power.config.json. The failure is isolated to shared_sharepointonline.
Repro steps
pa auth login (interactive user)
pa connection create --connector shared_sharepointonline (complete browser OAuth)
pa connection list-datasets --connector shared_sharepointonline --connection-id <new-connection-id>
Observe AuthenticationError / 403 "Missing Authorization header for a privileged call on connection" (product policy)
Environment
pa --version: 1.0.1pa auth login), not a service principalSymptom
Adding a SharePoint Online tabular data source fails with a 403 directly from the connector API Management layer:
Response body:
{ "Message": "Missing Authorization header for a privileged call on connection.", "Source": "product policy" }The same failure reproduces one level down, using
pa connection list-datasetsdirectly (no table/dataset involved at all):What I've ruled out
shared_sharepointonlineconnection viapa connection create --connector shared_sharepointonline(fresh interactive OAuth consent, browser sign-in completed successfully). The new connection fails identically with the sameAuthenticationError.pa connection listshows both connections owned by the currently authenticated user.pa connection listin the active environment, matchingenvironmentIdinpower.config.json.pa auth statusshows an interactive user account, not an app registration.list-datasetsstep, before any table/dataset value is involved.pa app add data-source --connector dataverse --table accountsucceeds cleanly in the same environment, same auth session, samepower.config.json. The failure is isolated toshared_sharepointonline.Repro steps
pa auth login(interactive user)pa connection create --connector shared_sharepointonline(complete browser OAuth)pa connection list-datasets --connector shared_sharepointonline --connection-id <new-connection-id>AuthenticationError/ 403 "Missing Authorization header for a privileged call on connection" (product policy)