Azure Data Factory · Authentication Profile

Microsoft Azure Data Factory Authentication

Authentication

Azure Data Factory secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the implicit flow(s).

Data IntegrationETLELTData PipelineData MovementOrchestrationData EngineeringChange Data CaptureIntegration RuntimeCloudAzureData Factory
Methods: oauth2 Schemes: 1 OAuth flows: implicit API key in:

Security Schemes

azure_auth oauth2
· flows: implicit

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: openapi/microsoft-azure-data-factory-activityruns-api-openapi.yml, openapi/microsoft-azure-data-factory-change-data-capture-api-openapi.yml,
  openapi/microsoft-azure-data-factory-credentials-api-openapi.yml, openapi/microsoft-azure-data-factory-data-flow-debug-session-api-openapi.yml,
  openapi/microsoft-azure-data-factory-data-flows-api-openapi.yml, openapi/microsoft-azure-data-factory-datasets-api-openapi.yml,
  openapi/microsoft-azure-data-factory-exposure-control-api-openapi.yml, openapi/microsoft-azure-data-factory-factories-api-openapi.yml,
  openapi/microsoft-azure-data-factory-global-parameters-api-openapi.yml, openapi/microsoft-azure-data-factory-integration-runtime-disable-interactive-query-api-openapi.yml,
  openapi/microsoft-azure-data-factory-integration-runtime-enable-interactive-query-api-openapi.yml, openapi/microsoft-azure-data-factory-integration-runtime-nodes-api-openapi.yml
  ...
summary:
  types:
  - oauth2
  oauth2_flows:
  - implicit
schemes:
- name: azure_auth
  type: oauth2
  flows:
  - flow: implicit
    authorizationUrl: https://login.microsoftonline.com/common/oauth2/authorize
    scopes: 1
  description: Azure Active Directory OAuth2 Flow.
  sources:
  - openapi/microsoft-azure-data-factory-activityruns-api-openapi.yml
  - openapi/microsoft-azure-data-factory-change-data-capture-api-openapi.yml
  - openapi/microsoft-azure-data-factory-credentials-api-openapi.yml
  - openapi/microsoft-azure-data-factory-data-flow-debug-session-api-openapi.yml
  - openapi/microsoft-azure-data-factory-data-flows-api-openapi.yml
  - openapi/microsoft-azure-data-factory-datasets-api-openapi.yml
  - openapi/microsoft-azure-data-factory-exposure-control-api-openapi.yml
  - openapi/microsoft-azure-data-factory-factories-api-openapi.yml
  - openapi/microsoft-azure-data-factory-global-parameters-api-openapi.yml
  - openapi/microsoft-azure-data-factory-integration-runtime-disable-interactive-query-api-openapi.yml
  - openapi/microsoft-azure-data-factory-integration-runtime-enable-interactive-query-api-openapi.yml
  - openapi/microsoft-azure-data-factory-integration-runtime-nodes-api-openapi.yml
  - openapi/microsoft-azure-data-factory-integration-runtime-object-metadata-api-openapi.yml
  - openapi/microsoft-azure-data-factory-integration-runtimes-api-openapi.yml
  - openapi/microsoft-azure-data-factory-linked-services-api-openapi.yml
  - openapi/microsoft-azure-data-factory-managed-private-endpoints-api-openapi.yml
  - openapi/microsoft-azure-data-factory-managed-virtual-networks-api-openapi.yml
  - openapi/microsoft-azure-data-factory-operations-api-openapi.yml
  - openapi/microsoft-azure-data-factory-pipelineruns-api-openapi.yml
  - openapi/microsoft-azure-data-factory-pipelines-api-openapi.yml
  - openapi/microsoft-azure-data-factory-private-endpoint-connections-api-openapi.yml
  - openapi/microsoft-azure-data-factory-private-link-resources-api-openapi.yml
  - openapi/microsoft-azure-data-factory-trigger-api-openapi.yml
  - openapi/microsoft-azure-data-factory-triggerruns-api-openapi.yml
  - openapi/microsoft-azure-data-factory-triggers-api-openapi.yml
docs: https://learn.microsoft.com/en-us/rest/api/azure/
searched_on: '2026-09-17'
discovery:
  openid_configuration: https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
  probed: '2026-09-17'
  status: 200
  saved: well-known/microsoft-azure-data-factory-openid-configuration.json
  issuer: https://login.microsoftonline.com/{tenantid}/v2.0
  authorization_endpoint: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
  token_endpoint: https://login.microsoftonline.com/common/oauth2/v2.0/token
  jwks_uri: https://login.microsoftonline.com/common/discovery/v2.0/keys
  id_token_signing_alg_values_supported:
  - RS256
runtime:
  header: 'Authorization: Bearer <access_token>'
  audience: https://management.azure.com/
  resource_scope: https://management.azure.com/.default
  api_keys: false
  note: The contract declares the legacy implicit flow against the v1.0 authorize endpoint. In practice Microsoft
    Entra ID issues tokens for this audience through the authorization-code flow with PKCE (interactive) or the
    client-credentials flow (service principal / workload identity), and Azure-hosted callers use a managed identity.
    Implicit is declared, not recommended; do not read it as the flow to implement.
authorization_model:
  style: azure-rbac
  note: The single delegated scope user_impersonation authenticates; it does not authorize. What a principal may
    do is decided by Azure role assignment on the factory, resource group or subscription. A token that lists factories
    fine will return 403 on a write if the role is missing, which is why 403 here means "assign a role", not "fix
    the token".
  roles:
  - name: Data Factory Contributor
    effect: full management of factories and their child resources
  - name: Contributor
    effect: full management including role-free resource operations
  - name: Reader
    effect: read-only across the factory surface
  - name: Owner
    effect: full management plus role assignment
  docs: https://learn.microsoft.com/en-us/azure/data-factory/concepts-roles-permissions
secret_handling:
  note: 'Two operations return live secrets: IntegrationRuntimes_ListAuthKeys and Factories_GetDataPlaneAccess.
    Treat both responses as credentials. Linked-service secrets should be held in Key Vault and referenced with
    AzureKeyVaultSecretReference rather than inlined into a definition.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/microsoft-azure-data-factory-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.