Skip to main content

Our Tableau Cloud site is configured with Microsoft Entra ID (Azure AD) SSO, and all user authentication is federated. We do not allow local Tableau usernames/passwords. 

 

We are attempting to integrate Tableau Cloud with Zenoptics using Tableau REST APIs. Zenoptics requires authentication via a Personal Access Token (PAT). 

 

To generate a PAT, Tableau requires a user account to sign in. However: 

 

Our Azure / Entra ID administrators have confirmed that they cannot create a non-interactive “service account” with a traditional username and password. 

 

All Entra ID accounts are SSO-only and require interactive authentication. 

 

Therefore, there is no way to log in as a headless service account to generate or manage a PAT. 

 

Questions 

 

What is the recommended architecture for API-based integrations (such as Zenoptics) when Tableau Cloud uses Entra ID–only authentication? 

 

Is Tableau’s official guidance to: 

 

Use a licensed Entra ID user dedicated as a service principal (human account, non-MFA, non-expiring), or 

 

Use Connected Apps / OAuth instead of PATs, or 

 

Some other Tableau-supported approach? 

 

If PATs are still required, how does Tableau recommend customers securely create and rotate PATs when non-interactive service accounts are not possible in Entra ID? 

 

Please advise on the supported and secure best practice for this integration pattern in Tableau Cloud with Entra ID SSO enforced. 

 

#Tableau Cloud

1 个回答
  1. 9月15日 00:30

    Hi, @Winston Kaki

     

     

    It's been a while since this was posted, so you may have already found a solution. However, I wanted to share a thought in case it's helpful.

    If Zenoptics only supports PAT-based authentication, then using a dedicated licensed user account may be the most practical option.

    That said, this approach seems to introduce additional operational overhead around PAT management and rotation. Looking at Tableau's Connected Apps documentation, features such as SSO integration, JWT-based authentication, and secret rotation are supported. Because of that, it seems worth considering alternatives to PATs from both a security and governance perspective.

    However, from what I have been able to find, I have not seen any Tableau documentation that explicitly states which approach is considered the best practice for Entra ID SSO-only environments. So while Connected Apps or OAuth appear to be promising options, I'm not sure which architecture Tableau officially recommends for this type of integration.

    I'd also be interested to hear from anyone running a similar setup, or from someone familiar with Tableau's official guidance on this topic.

0/9000