---
sourceDocument: Australia Employee Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/employee-service-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Update Outlook Actionable Messages authentication to Microsoft Entra ID

# Update Outlook Actionable Messages authentication to Microsoft Entra ID {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Microsoft will retire External Access Token (EAT) authentication for Outlook Actionable Messages on March 31, 2026. Microsoft Entra ID token authentication is required for Outlook Actionable Messages.

## Before you begin

Role required: admin

## About this task

Warning:  
After Microsoft retired External Access Token (EAT) authentication for Outlook Actionable Messages on March 31, 2026, actionable messages that rely on EAT will stop working.

To ensure uninterrupted functionality with actionable message, you must migrate to Microsoft Entra ID token authentication and update the Outlook Actionable Messages app registration in your ServiceNow instance.

## Procedure

1. Complete the Microsoft Entra ID setup for Actionable Messages.  
   For more information, refer to [Enabling AAD token of Actionable Messages](https://learn.microsoft.com/en-us/outlook/actionable-messages/enable-entra-token-for-actionable-messages).  
   Important:  
   If you already have an AM provider with Microsoft, migrate and regenerate the AM provider ID. If you do not have one, generate a new provider ID.
2. After completing the setup, copy the App ID Uri and the Provider Id (originator).  

3. On your ServiceNow instance, update the sn_ms_oam.outlookactionable.originator System property value with the new Provider Id (originator) copied from Step 2.
4. Navigate to AllSystem OAuthApplication Registry.
5. Select Outlook Actionable.
6. On the form, in the Client ID field, update the ID with the App ID Uri that you copied in Step 2.
7. In the OAuth OIDC Provider Configuration field, open the Microsoft Office record.  
   On the Microsoft Office OIDC Provider Configuration form, do the following:

   1. Update the OIDC Metadata URL to this format: <kbd class="ph userinput">https://sts.windows.net/{tenant-id}/.well-known/openid-configuration</kbd>.
   2. Set the User Claim field to upn.  
   3. Save the form.
   {#update-outlook-actionable-msgs-auth-to-ms-entra-id__substeps_nbj_y5b_m3c}
8. Save the form.
{#update-outlook-actionable-msgs-auth-to-ms-entra-id__steps_c41_2rd_m3c}

## Result

You are now migrated to Microsoft Entra ID token authentication and the Outlook Actionable Messages app registration is updated in your ServiceNow instance.

*[\>]: and then


