Hello @ShwetaD, I took a look at both internal and external documentation and here is what I found.
@cassie258elks has the right first move. One thing to understand about that error: the Power BI service generates it, and the service keeps its own copy of your credentials. Power BI Desktop caches a separate copy on your machine, so a source can look connected on your side while the published semantic model has a credential that's missing, expired, or invalid. Only the service's copy matters for scheduled refresh. I'm assuming a Databricks SQL warehouse is behind the model since you posted here.
The usual ways the service's copy goes bad, in the order I'd check:
- Every source in the model needs credentials, not just Databricks. A CSV, SharePoint list, or web source with nothing bound blocks refresh for the whole model, even if you've turned refresh off for it.
- You republished after changing the server hostname or HTTP path. The service treats that as a new data source with nothing stored.
- The Databricks credential itself died. With user OAuth, Databricks issues single-use refresh tokens to the Power BI service by default; a refresh that fails mid-flight can burn the old token before the new one is stored, and from then on the connection needs a manual sign-in. @emma_s (Databricks) explained this in the thread linked below. With the PAT option, a personal access token was created for you, and those expire, get revoked, or vanish with the account that owns them. A password change or an Entra ID conditional access policy can also kill a user OAuth grant.
- You're not the owner. Only the semantic model owner can edit credentials. If someone else published it, click Take over on the settings page first.
To get refresh running again:
- Open the semantic model and choose Refresh > Refresh history. The error there names the exact failing source, which tells you which case you're in.
- Choose Refresh > Schedule refresh to reach the settings page, expand Data source credentials, and click Edit credentials on every source, the Databricks one included. The quickest path is to re-authenticate with the same method the connection already uses: OAuth2 to sign in as yourself, a personal access token, or Basic with a service principal's application ID as the user name and its OAuth secret as the password. Also confirm that identity still has
CAN USE on the warehouse and SELECT on the tables; a lost grant looks identical to a bad credential. If the whole section is greyed out and a gateway is in play, the gateway admin owns the credentials. If there's no gateway, go back to Desktop, open Transform data > Data source settings, look for a source that's not signed in or points at a local file path, fix it, and republish.
- Click Refresh now. When it passes, set the Configure a refresh schedule slider back to On and click Apply. Power BI deactivates the schedule after four consecutive failures or an unrecoverable credential error and won't turn it back on for you.
If Edit credentials itself fails with Unauthorized or Forbidden, check whether the Databricks workspace sits behind Private Link or IP access lists. Databricks notes you may need an on-premises data gateway in that setup.
To stop this from coming back, move the Databricks source off a personal login and onto a service principal with M2M OAuth: create the service principal, give it an OAuth secret, grant it SELECT on the tables and CAN USE on the warehouse, then use the Basic option from step 2. Nothing is tied to a person, so password resets, conditional access, departures, and the single-use token problem all stop mattering. On Azure, use a Databricks-managed service principal rather than an Entra ID managed one; the Azure docs say the Entra flavor caps a refresh at one hour because the connector can't renew the token.
If you're still stuck, the most useful details are the exact Refresh history error, how you authenticated to Databricks (OAuth, PAT, or service principal), whether you published from Desktop or used Publish to Power BI from Databricks, whether the model is Import or DirectQuery, and whether a gateway is involved. Please redact tokens, secrets, and anything tenant or workspace specific.
References:
Regards, Louis.