Does anybody know how technically exactly Jira Service Management integrates with Microsoft 365 mailboxes? Which OAuth grant type is used and if it somehow tied to the machine the integration was set-up the first time?
We had a custom email address configured for at least couple of years now. It worked perfectly fine to this day, but today it started to produce Connection access token retrieval errors until it was rate limited by Jira itself. On Microsoft side the audit log for the mailbox said:
Failure reason: Device object was not found in the tenant '{tenantName}' directory.
Additional Details: Invalid grant due to the following reasons: - Requested SAML 2.0 assertion has invalid Subject Confirmation Method - Application On-Behalf-Of flow is not supported on V2 - Primary refresh token is not signed with session key - Invalid external refresh token - The access grant was obtained for a different tenantThe only thing that changed exactly at the same time errors started to appear was that my own PC was reinstalled and rejoined to Microsoft Azure AD. This is the same PC I set-up Microsoft email integration in Jira Service Management from.
Is this a bug or known limitation?