---
sourceDocument: Xanadu Employee Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/employee-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Authorize pre-published SSO and Activity Notification Azure apps to grant required permissions

# Authorize pre-published SSO and Activity Notification Azure apps to grant required permissions {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Authorize the pre-published SSO and Activity Notification apps to enable ServiceNow® to make API calls from a personal tab in Microsoft Teams.

## Before you begin

Role required: External admin (external_app_install_admin)

## About this task

To connect your ServiceNow instance to your Microsoft 365 tenant and to Authorize apps, the user must have both the external_app_install_admin role and the application administrator role in Microsoft 365. Application administrator is a Microsoft driven role, for more information on roles, refer [Azure AD built-in roles](https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#available-roles).

## Procedure

1. Navigate to AllServiceNow for Microsoft 365Install Azure apps.
2. Select Authorize for SSO and Activity Notification.
3. Provide the admin consent by selecting Accept.  
   Note:  
   Additional permissions such as 'Manage Teams apps for all chats' and 'Allow the Teams app to manage all tabs for all chats' are required to create an app for meeting extensibility, and to create a new tab for a major incident meeting from the major incident workbench in Microsoft Teams.

   Upon successful authorization, the app status is displayed as Installed.

*[\>]: and then


