SAP Knowledge Base Article - Public

3722141 - ADLS connection fails with "forbidden" error in SAP Datasphere

Symptom

ADLS connection validation is failing with the error message: "Possible causes of error: Detailed error message (forbidden)"

Environment

SAP Datasphere

Reproducing the Issue

  1. Go to "Connections"
  2. Validate the Microsoft Azure Data Lake Storage Gen2 connection
  3. Connection validation fails with: "Data Flows: Cause: Possible causes of error: Detailed error message (forbidden)
    Replication Flows: Cause: Possible causes of error: Detailed error message (forbidden)"

Cause

The issue is caused:

  1. missing network configuration adjustments, specifically the allowance of the SAP Datasphere VNET Subnet in the firewall rules of the Azure storage account.

or if all the resources which are added to the related pvt storage end points are reachable (green and reachable) from Cloud Connector:

      2. String for OAuth should be picked based on the OAuth token endpoint used in the Datasphere connection. 

Resolution

1. Refer to the prerequisites outlined in the Microsoft Azure Data Lake Store Gen2 Connections: update the Azure Storage allow list, adding the VNet/Subnet of the SAP Datasphere cluster.

2. Check if the string for OAuth is the same as the OAuth token endpoint used in the Datasphere connection. 

See Also

How to create the necessary mappings in Cloud Connector to enable private data routing

Obtain SAP Datasphere IP addresses For Allowlisting in Remote Systems

Keywords

KBA , DS-DI-CON , Connections , Problem

Product

SAP Datasphere all versions