Obtain an Entra app ID for BEMS with certificate-based authentication

If you need to obtain multiple Entra app IDs (for example, Docs and BlackBerry Work), it is recommended that you create a separate app ID for each app.
  1. Sign in to entra.microsoft.com.
  2. In the left column, click Applications > App registrations.
  3. Click New registration.
  4. In the Name field, enter a name for the app.
  5. Select a supported account type.
  6. Click Register. The new registered app appears.
  7. In the Manage section, click API permissions.
  8. Click Add a permission.
  9. In the Select an API section, click APIs my organization uses.
  10. Search for and click Office 365 Exchange Online.
  11. Click Application permission and select the full_access_as_app (Use Exchange Web Service with full access to all mailboxes) permission.
  12. Click Add permissions.
  13. In the Configured permissions section, click Microsoft Graph.
  14. Click Application permissions and select the following permissions:
    • Contacts.ReadWrite (Have full access to user contacts)
    • Mail.Read (Read user mail)
    • User.Read.All (Read all users' full profiles)
  15. Click Add permissions.
  16. Click Grant admin consent.
  17. Click Yes.
  18. Click Overview to view the app that you created in step 5. Copy the Application (client) ID. The Application (client) ID is displayed in the main Overview page for the specified app. This is used as the Client application ID in the BEMS dashboard when you enable modern authentication and configure BEMS to communicate with Microsoft Exchange Online.
Associate a certificate with the Entra app ID for BEMS