Error 401 when trying to access a Private Endpoint

Charly Gerald 20 Reputation points
2026-02-20T19:54:52.3233333+00:00

A private endpoint request from Microsoft Fabric to an Azure SQL DB is displaying the following message:

{

"sessionId":"62903e40ca1f4055b7f7fe24e30d261b"

,"subscriptionId":"171c93d8-7864-4c53-842b-36ff98e977b8"

,"resourceGroup":"vnet-171c93d8-EastUS-189-rg"

,"errorCode":"401"

,"resourceId":"/subscriptions/171c93d8-7864-4c53-842b-36ff98e977b8/resourceGroups/vnet-171c93d8-EastUS-189-rg/providers/Microsoft.Network/privateEndpoints/553f0c4f-bacf-45ee-8afb-4973685c896b.mpe_azuredb_fabric",

"resourceName":"553f0c4f-bacf-45ee-8afb-4973685c896b.mpe_azuredb_fabric"

,"details":

	"The access token is from the wrong issuer 'https://sts.windows.net/6a6131c7-ecda-42b0-bf16-ec3dbd397f92/'. 

	It must match the tenant 'https://sts.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d/' associated with this subscription. 

	Please use the authority (URL) 'https://login.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d' to get the token. 


	

	Note, if the subscription is transferred to another tenant there is no impact to the services, but information about new tenant 

	could take time to propagate (up to an hour). If you just transferred your subscription and see this error message, please try back later."
```}

I have noticed that the Azure DB's Resource ID does not match my Tenant ID.  
  
I need help

Azure SQL Database

1 answer

Sort by: Most helpful
  1. AI answer

    2026-02-20T19:55:03.98+00:00

    The error you are encountering (401 Unauthorized) indicates that the access token being used is from the wrong issuer. Specifically, it mentions that the token must match the tenant associated with your subscription. Here are some steps you can take to resolve this issue:

    1. Check Tenant ID: Ensure that you are using the correct tenant ID when requesting the access token. The error message specifies that you should use the authority URL https://login.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d to obtain the token.
    2. Token Acquisition: When acquiring the token, make sure that the request is made to the correct tenant. This typically involves specifying the tenant ID in your authentication request.
    3. Subscription Transfer: If you have recently transferred your subscription to a different tenant, it may take some time for the changes to propagate. If this is the case, you might need to wait for up to an hour and try again.
    4. Verify Resource ID: As you noted, the Azure DB's Resource ID should align with your Tenant ID. Ensure that the resource you are trying to access is indeed associated with the tenant you are using to authenticate.
    5. Permissions: Ensure that the account you are using has the necessary permissions to access the Azure SQL Database through the private endpoint.

    By following these steps, you should be able to resolve the 401 error and successfully connect to your Azure SQL Database through the private endpoint.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.