Troubleshooting Power Query's Unexpected 401 Authentication Loop

Are you experiencing repeated 401 errors with every Power Query Web.Contents request today? It seems that Power Query is now issuing multiple 401 challenges instead of efficiently caching your authentication token. This…

3 min readMicrosoft Excel | Help & Support with your Formula, Macro, and VBA problems | A Reddit Community

We have a clear opinion on this: Power Query broke something it should not have broken, and users are bearing the cost of a silent regression. The report from one developer is a canary in the coal mine for anyone relying on OAuth-connected APIs in Excel or Power BI. When a tool that previously cached a token across requests suddenly forces a full authentication handshake on every single call, it is not a minor quirk, it is a performance and reliability problem that compounds with every refresh.

What this means for you in practical terms is measurable. Each request now adds roughly 70 microseconds of unnecessary 401 traffic before the token is even presented. That might seem trivial for a single query, but scale it across dozens of endpoints, hundreds of rows, or scheduled refreshes in a production dashboard. The latency stacks, the logs fill with noise, and your API might start rate-limiting what it sees as suspicious repeated challenge requests. Worse, the timing, March 1st, strongly suggests an Office update rolled out a change to the authentication flow without documentation or opt-out. That is not how you treat users who depend on predictable behavior.

The developer who posted this did the right thing: they checked their own backend, confirmed nothing changed on their side, and then looked for community confirmation. That is the kind of methodical troubleshooting we should all emulate. But the burden should not be on individual users to reverse-engineer Microsoft's update cadence. The fix here is not a workaround in Power Query M code or a tweak to the API's challenge response. The fix is for the Power Query team to restore token caching to its previous behavior, or at minimum to publish a changelog entry explaining why the flow changed and how to adapt.

Until then, check your own refresh logs. If you see a sudden uptick in 401 responses followed by 200s on every call, you are likely affected. Document the pattern, open a support ticket, and reference this community thread. The more noise we make, the harder it is for this regression to stay silent.

From Microsoft Excel | Help & Support with your Formula, Macro, and VBA problems | A Reddit Community

I have an API that Power Query connects to using Organizational Account authentication (Entra ID / Azure AD). The API returns the standard WWW-Authenticate challenge header so Power Query can discover the auth endpoint and acquire a token.

The expected behavior was: Power Query sends one unauthenticated request, gets the 401 challenge, acquires a token, and then reuses it for all subsequent requests — so you'd see one initial 401 followed by all 200s.

Read the original at Microsoft Excel | Help & Support with your Formula, Macro, and VBA problems | A Reddit Community