<h2>SSO Application Status is showing status failed</h2><br/><div style="overflow-x:auto"><article><div ><h3 >Issue </h3><section><p style="text-align: left; padding-left: 40px;">SSO Application's Status is failing with status "failed"</p> <ul style="list-style-position: inside;"><li>The Outbound is failing with<br />{"error":{"code":"Authentication_RequestFromUnsupportedUserRole","message":"User is not in the allowed roles","innerError"</li></ul></section></div><div ><h3 >Cause</h3><section><p style="text-align: left; padding-left: 40px;">Global admin role is missing for the user who fetched the OAuth token</p> <p style="text-align: left; padding-left: 40px;">To check which fetched the OAuth token:</p> <ul style="list-style-position: inside;"><li>Navigate to System OAuth > Manage Tokens.</li><li>Find the token with the name of Azure and add the User column.</li></ul></section></div><div ><h3 >Resolution</h3><section><ol style="list-style-position: inside;"><li style="text-align: left;">Check the user roles of the user who fetched the OAuth token on Azure AD, iF GLOBAL Admin role is missing then add the role to that user.</li><li style="text-align: left;">If Azure team denies for provide the Admin role to that user then use the already existing user who've admin role to fetch the OAUTH</li></ol> <ul><li style="list-style-type: none;"> <ul style="list-style-position: inside; list-style-type: disc;"><li>Open an incognito browser window</li><li>Login to Azure AD with the user who has Global admin access to Azure portal</li><li>Login to ServiceNow, open the connection record and complete the auth steps (if already done, open Connection > Credential > Click on Generate OAuth Token).</li></ul> </li></ul></section></div></article></div>