Our Tableau Cloud site is configured with Microsoft Entra ID (Azure AD) SSO, and all user authentication is federated. We do not allow local Tableau usernames/passwords.
We are attempting to integrate Tableau Cloud with Zenoptics using Tableau REST APIs. Zenoptics requires authentication via a Personal Access Token (PAT).
To generate a PAT, Tableau requires a user account to sign in. However:
Our Azure / Entra ID administrators have confirmed that they cannot create a non-interactive “service account” with a traditional username and password.
All Entra ID accounts are SSO-only and require interactive authentication.
Therefore, there is no way to log in as a headless service account to generate or manage a PAT.
Questions
What is the recommended architecture for API-based integrations (such as Zenoptics) when Tableau Cloud uses Entra ID–only authentication?
Is Tableau’s official guidance to:
Use a licensed Entra ID user dedicated as a service principal (human account, non-MFA, non-expiring), or
Use Connected Apps / OAuth instead of PATs, or
Some other Tableau-supported approach?
If PATs are still required, how does Tableau recommend customers securely create and rotate PATs when non-interactive service accounts are not possible in Entra ID?
Please advise on the supported and secure best practice for this integration pattern in Tableau Cloud with Entra ID SSO enforced.
#Tableau Cloud