Obtain an Entra app ID for BEMS with client secret authentication
- Sign in to entra.microsoft.com.
- In the left column, click Applications > App registrations.
- Click New registration.
- In the Name field, enter a name for the app.
- Select a supported account type.
- Click Register.
- In the Manage section, click API permissions.
- Click Add a permission.
- Click Microsoft Graph.
- Click Application permissions and set the following permissions:
- Read mail in all mailboxes (Mail > Mail.Read)
- Read all user's full profile (User > User.Read.All)
- Read and write contacts in all mailboxes (Contacts > Contacts.ReadWrite)
The Contacts.ReadWrite permission is only required if you require the Contact Service API to use third-party apps to query, retrieve, create, and update contact information from a user’s contact folder. For more information, see the Contact Service API reference content.
- Click Add permissions.
- Click Grant admin consent. Click Yes.
- Add a client secret.