In order to receive the identity token that is used to decrypt DKE, you must register with Azure Entra or the Azure Portal. You must have an account in order to access one of these pages.
To register with Azure Entra
Navigate to https://entra.microsoft.com/.
Navigate to the App registrations page by clicking on App registrations in the 'Entra ID' section on the left, or by searching for App registrations using the search bar at the top of the page.
On the App registrations page, click New registration.
On the Register an application page, enter the name to use for the application.
Select the supported account type. You must select one of the following:
Accounts in this organizational directory only (MSFT only - Single tenant)
Accounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant)
For the Redirect URI, select Web and enter the FQDN of the service.
Click Register.
On the App registration page for the application that you just registered, click Expose an API.
On the Expose an API page, enter the FQDN in the Application ID URI field, then click Save.
Click Add a scope.
In the Add a scope window, enter user_impersonation for the Scope name, Admin consent display name, and Admin consent description.
Click Add scope to return to the Expose an API page.
Click Add a client application.
In the Add a client application window, enter the Microsoft Office client ID.
d3590ed6-52b3-4102-aeff-aad2292ab01cCheck the checkbox for the scope you just added, then click Add application.
Click Add a client application again and enter the Azure Information Protection unified labeling client ID.
c00e9d32-3c8d-4a7d-832b-029040e7db99Check the checkbox for the scope and click Add application.