Authenticating Using AzureGraph

#132 · closed · 3 comments

View on GitHub ↗

DOH-WLD0303

I've been trying to identify if it is possible to authenticate using Azure Active Directory as a user without the need to register an application in Azure. The vignette located here: https://cran.r-project.org/web/packages/AzureStor/vignettes/aad.html shows how to do this with an application but does not show how to do it as an individual user. This might be because it isn't possible but it seems like it should be possible when combined with AzureGraph. My use case is to read a file from ADLS after authenticating to AAD as myself, this is similar to #79 but doesn't mention the use of AzureGraph. My code that I'm using is below: ```r library(AzureStor) library(AzureGraph) tenant <- 'xxxxx-xxxx-xxxx-xxxxxxx' gr <- create_graph_login(tenant) adls <- AzureStor::adls_endpoint(endpoint='https://NAME_OF_STORAGE_ACCOUNT.dfs.core.windows.net/', token=gr$token$credentials$access_token) cont <- AzureStor::adls_filesystem(adls, 'NAME_OF_CONTAINER') AzureStor::list_adls_files(cont) AzureStor::storage_read_csv(cont, 'PATH/TO/MY/FILE.CSV') ``` Both of the last two commands fail with an unauthorized 401 error. Is this method of accessing ADLS completely unsupported and registering an app is the only option?

Comments

mwferris

You can use the `AzureAuth` library and the `Microsoft Azure CLI` appplication id `04b07795-8ddb-461a-bbee-02f9e1bf7b46` found [here](https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in). This is how the Azure KeyVault R library and Python SDK do it. ``` token <- AzureAuth::get_azure_token(resource = "https://storage.azure.com", tenant = "<your-tenant>", app = "04b07795-8ddb-461a-bbee-02f9e1bf7b46") storage <- storage_endpoint(<your endpoint>, token = token) ```

DOH-WLD0303

This resolved the issue, thanks mwferris!

mattkumar

Hi there, I'm trying to do something similar to the use-case described above. I can confirm the methods here work in a local R studio setting. However, I'm trying to implement/extend the above to a shiny app. The shiny app will be deployed within our companies Connect server. If I use this approach, I need to provide a redirect as outlined [here.](https://cran.r-project.org/web/packages/AzureAuth/vignettes/shiny.html) The issue I get is when the app is deployed, it says no redirect is associated with app "04b07795-8ddb-461a-bbee-02f9e1bf7b46". Is it possible to set one in Azure for this particular app? I'm not so fluent with Azure but am working closely with some devs. I was hoping to have this as a solution soon. Our use case is similar to the above (i.e. wanting to login as a user, access a file container as a user). Right now, we have a separate storage container, app, tenant setup that does work with the redirect. It requires an app password which I have. I can access the files fine in the deployed shiny app but I am doing so as the app, not necessarily the user. Any guidance on this would be helpful. Have worked through a bunch of scenarios, some of which seem to work locally, but don't once put into a shiny app and deployed. @mwferris Thanks so much.