Access Token Issue - Entra Integration
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
The integration works successfully when I click Get Oauth and then manually execute the scheduled job.
However, the scheduled jobs are failing when they run at their scheduled time. The access token appears to be valid for only around 30 minutes. After that, the scheduled job fails because the token is not being automatically refreshed before or during execution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
The pattern where it works right after you click the button and dies on the schedule usually isn't a refresh problem, it's that you're the one getting the token.
Two things I'd look at first. The grant type has to say the same thing in two places, the Application Registry record and the OAuth entity profile. I've run into setups where the registry says client credentials but the profile is still sitting on authorization code, and the platform keeps trying to send someone through an interactive login, which is never going to happen at 2am. The other one, if you are on client credentials then there is no refresh token at all, by design, so there's nothing to refresh and ServiceNow should just be asking for a fresh one each run. If you're on authorization code, the token is tied to the consent you gave and it will keep dying on you.
Side note, 30 minutes isn't an Entra default, they're normally 60 to 90. ServiceNow's own instance tokens are 30 though, so it's worth checking which token you're actually looking at.
1. What grant type is set, and does it match on both the Application Registry and the OAuth entity profile?
2. What's the verbatim error when it fails on schedule, from the job log or the outbound HTTP log?
3. What makes the call, a REST Message, a flow using a connection alias, or a RESTMessageV2 script?
4. Where did you click Get OAuth Token, on the Application Registry or on the REST Message itself? They don't put the token in the same place.
If that works for you, mind marking it as the recommended solution? Helps me support these better for the community.
