---
sourceDocument: Xanadu ServiceNow AI Platform Administration
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/platform-administration

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu ServiceNow AI Platform Administration

ft:clusterId :

    - platadm

bundleId :

    - platadm

workflow :

    - Platform


---

# Configure an OAuth profile to use a client ID and secret for token generation

# Configure an OAuth profile to use a client ID and secret for token generation {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Configure an OAuth profile using a client ID and client secret to create an email
account for using Microsoft Graph (receive) in your email account
type.

## Before you begin

Create an [Microsoft Azure](https://portal.azure.com) account to configure OAuth profile.

Complete the set up steps using your Microsoft Azure Developer
account. See the [Microsoft Azure product documentation](https://docs.microsoft.com/en-us/azure/) for instructions
on creating and configuring custom applications.

Role required: admin and Microsoft Azure portal administrator

## Procedure

1. Log in to the Microsoft Azure registration portal with your organization credentials.  
   For more information, see the Microsoft Azure [registration portal
   documentation](https://portal.azure.com/#blade/Microsoft_AAD_RegisteredApps/ApplicationsListBlade).
2. Register a new custom application by filling in the application name, supported account type, and redirect URI, and select Register.  
   Note:  
   Enter the redirect URI in the following format: <kbd class="ph userinput">https://&lt;instance&gt;/oauth_redirect.do</kbd>.  
   An overview of the application's basic information is displayed.
3. Copy the client ID to a text file.  
   You will use this ID and the client secret value generated in the next steps to register the app as a third-party OAuth provider on your ServiceNow instance. You use the application ID as the client ID when you connect the application to your instance.
4. Enable the Mail.ReadWrite permission.
   1. In Microsoft Azure, navigate to ManageAPI permissions.
   2. Select Add a permission.
   3. Select the Microsoft Graph tile.
   4. Select Application Permissions.
   5. In the Select permissions field, enter <kbd class="ph userinput">Mail.ReadWrite</kbd>.
   6. Select the Mail.ReadWrite check box.
   7. Select Add permissions.
   {#microsoft-graph__substeps_ddd_zft_whb}
5. Select Grant admin consent for \<your organization name\>.
6. Select Yes to confirm.
7. Add a client secret.
   1. In Microsoft Azure, navigate to ManageCertificates \& secrets.
   2. Select New client secret.
   3. Provide a description and an expiration date and select Add.
   {#microsoft-graph__substeps_dzd_nct_whb}
8. Copy the value (secret value) to a text file.
9. Navigate to OverviewEndpoints and copy the OAuth 2.0 token endpoint (v2) to a text file.
{#microsoft-graph__steps_bbj_tfz_ztb}
**Related tasks**   

* [Activate Email - Support for Email Processing by Microsoft Graph API](https://servicenow-prod.fluidtopics.net/W0DLVUmLLLahmXhc1qbCXg "You can activate the Email - Support for Email Processing by Microsoft Graph API plugin (glide.email.graph) for Notifications if you have the admin role.")
* [Configure an OAuth profile to use certificates for authentication with Microsoft Azure](https://servicenow-prod.fluidtopics.net/GkjDXa7ZkiaCNyCbZJgROg "Configure an OAuth application profile to authenticate using certificates.")
* [Create an email account for Microsoft Graph (receive)](https://servicenow-prod.fluidtopics.net/9GY~GfNmI7fsVNPPwqOs_A "Create an email account for reading emails from Microsoft Exchange Online using Microsoft Graph Endpoints.")

## Register an application as an OAuth provider {#ariaid-title2}

Use the information generated during Microsoft Azure account
configuration to register an application as an OAuth provider.

### Before you begin

Role required: admin

### Procedure

1. Navigate to AllSystem OAuthApplication Registry.
2. Select New.
3. On the What kind of OAuth application screen, select Connect to a third-party OAuth Provider.
4. On the form, fill in the fields.  
   {#register-an-application-oauth-provider__table_alw_kq3_gfb__entry__2}

   | Field | Value required |
   |-|-|
   | Name | Name to uniquely identify the record. |
   | Client ID | Application ID of the application you created in Microsoft Azure. |
   | Client Secret | The client secret you generated when you created the application in Microsoft Azure. Note: When using certificates, the Client Secret is a dummy value. |
   | OAuth API Script | OAuth API script name. For more information see, [OAuth API Script](https://servicenow-prod.fluidtopics.net/b8hhfYNNHvB_RAgu8IzVEg "Create and duplicate OAuth API script for application registry."). Note: This is required only while using certificates. |
   | Default Grant type | Client Credentials. |
   | Token URL | Token URL copied after configuring the Microsoft Azure account. |
   | Redirect URL | <kbd class="ph userinput">https://&lt;instance&gt;./oauth_redirect.do</kbd> Note: This URL should be the same as the URL in Microsoft Azure. |
   [Table 1. Application Registries form]

   {#register-an-application-oauth-provider__table_alw_kq3_gfb}
5. Right-click the form header and select Save.  
   An OAuth Entity Profile record is created.
6. In the OAuth Entity Scopes related list, add scopes to match the permissions you defined when you configured the application.
7. Select Insert a new row.
8. Enter <kbd class="ph userinput">Default</kbd> as the name and <kbd class="ph userinput">.default</kbd> as OAuth scope.
9. Right-click the form header and select Save.
10. In the OAuth Entity Profiles embedded list, select the profile created by default.
11. In the OAuth Entity Scopes embedded list, add a new row and select the Default scope.
12. Select Update.

### What to do next

[Create an email account for Microsoft Graph (receive)](https://servicenow-prod.fluidtopics.net/9GY~GfNmI7fsVNPPwqOs_A "Create an email account for reading emails from Microsoft Exchange Online using Microsoft Graph Endpoints.") using the OAuth profile.

*[\>]: and then


