Skip to main content
Winston Kaki ha preguntado en #Tableau Cloud

Our Tableau Cloud site is configured with Microsoft Entra ID (Azure AD) SSO, and all user authentication is federated. We do not allow local Tableau usernames/passwords. 

 

We are attempting to integrate Tableau Cloud with Zenoptics using Tableau REST APIs. Zenoptics requires authentication via a Personal Access Token (PAT). 

 

To generate a PAT, Tableau requires a user account to sign in. However: 

 

Our Azure / Entra ID administrators have confirmed that they cannot create a non-interactive “service account” with a traditional username and password. 

 

All Entra ID accounts are SSO-only and require interactive authentication. 

 

Therefore, there is no way to log in as a headless service account to generate or manage a PAT. 

 

Questions 

 

What is the recommended architecture for API-based integrations (such as Zenoptics) when Tableau Cloud uses Entra ID–only authentication? 

 

Is Tableau’s official guidance to: 

 

Use a licensed Entra ID user dedicated as a service principal (human account, non-MFA, non-expiring), or 

 

Use Connected Apps / OAuth instead of PATs, or 

 

Some other Tableau-supported approach? 

 

If PATs are still required, how does Tableau recommend customers securely create and rotate PATs when non-interactive service accounts are not possible in Entra ID? 

 

Please advise on the supported and secure best practice for this integration pattern in Tableau Cloud with Entra ID SSO enforced. 

 

#Tableau Cloud

0/9000