To discover and back up workspaces in the Druva console, you must complete specific configurations in your Microsoft Azure and Power BI environments. These steps enable the Druva Service Principal to access the required APIs.
Prerequisites
Use the following prerequisite steps as a checklist before you begin configuration in the Druva console.
Prerequisite step | Why this is required | Who should perform this |
Create/update Azure Security Group with name | Creates a dedicated identity container in Entra ID so the Druva service principal has a security group–scoped identity that can be granted least‑privilege access to Power BI/Fabric APIs. | Azure AD / Entra ID administrator with permissions to create security groups and manage enterprise applications. |
Authorize the security group for Power BI Admin and Fabric public APIs | Grants the security group created in step 1, permission to call Fabric public APIs, read‑only admin APIs, and create workspaces during restore so Druva can discover and list tenant workspaces without tenant‑wide admin rights. If skipped, Druva cannot scan the tenant and discovery will not begin; restore to a new workspace will also fail. | Power BI service administrator or Fabric administrator with access to the Power BI Admin portal tenant settings. |
Step 1: Create/update Azure Security Group
Objective: Create a standard Security Group in Azure to house the Druva service principal.
Access Azure: Log in to the Azure Portal.
Create Security Group: Navigate to Entra ID > Groups > New group.
Group type: Select Security.
Group name: Enter the exact name:
DRUVA-SG-DPPSPN-DR.
⚠️ Important: The security group name must match exactly. If the name does not match this value, reports will not be backed up.
Group Description: Provide a description for this group.
Add Druva Application Member:
Open the newly created group and select Members > Add members.
Search Criteria: Search for the application name
Druva Powerplatform.Action: Select the application and click Select to add it to the group.
Summary: You have created a container (Security Group) with the exact name DRUVA-SG-DPPSPN-DR and added the Druva service principal (Druva PowerPlatform app) as a member to enable identity-based permissions.
Step 2: Authorize Power BI Admin and Fabric Public APIs
Objective: Grant the Security Group created in Step 1 permission to access Power BI Admin read-only APIs and to create workspaces during Power BI restore.
Access Admin Settings: Log in to the Power BI Admin Portal.
Locate API Settings: Navigate to Tenant settings > Admin API settings.
Configure ‘Service Principal settings’:
Under Developer settings, enable both of these settings. Use the same process for each:
Service principals can call Fabric public APIsService principals can create workspaces, connections, and deployment pipelinesSet the toggle to Enabled.
Define Access Scope:
Under Apply to, select the radio button for Specific security groups.
Search: Enter the name of the Security Group created in Step 1 (
DRUVA-SG-DPPSPN-DR).Click Apply.
📝NOTE: The Service principals can create workspaces, connections, and deployment pipelines setting is required because Druva automatically creates the target workspace when restoring data to a new workspace. If this setting is disabled, the restore fails with a Microsoft permission error, such as MS-248.
Find the setting:
Service principals can access read-only admin APIsunder Admin API Settings section.
Summary: By enabling the Service Principal setting for a specific group, you have authorized the Druva application to call Power BI APIs without granting tenant-wide administrative rights.
📝NOTE:
If the Azure environment setup is complete but discovery is not working, ensure that KMS is configured. Without KMS enabled, discovery will not initiate.
After you enable or update any tenant setting in Step 2, allow 15–20 minutes for Microsoft to propagate the change before you retry discovery or restore.
Important: Synchronization Latency Microsoft may require up to 24 hours to synchronize permission changes across the environment.
Verify Discovery Status
After configuration, Druva automatically scans the tenant. Check the Status Indicators:
Connected: The app is successfully authenticated.
Discovery Not Started: This status appears if the Azure prerequisites (Security Group/API settings) are not detected. You must complete the steps before discovery can proceed.
Once all prerequisites are met, discovery begins automatically. After the environment scan is complete, the system populates the list of workspaces.

