...
Turn on System-assigned managed identity for the App Service
Assign to the App Service identity root level permissions to the App Service
Assign the App Service to the Global Administrator role for the tenant
These steps ensure that EmpowerID has the appropriate authentication and access to read and write the user information in for your Azure AD and subscriptiontenant.
To turn on System-assigned managed identity for the App Service
...
In Azure navigate to Management groups.
Click the details link beside Tenant Root Group.
On the tenant root page, click Access Control (IAM) in the sidebar.
On the Access Control (IAM) page, click Add and then select Add role assignment.
In the Add role assignment pane that appears, click Select a role and then select Owner.
Search for and select the App Service you deployed to the tenant.
Save the role assignment.
Assign the App Service to the Global Administrator role for the tenant
Navigate to Azure Active Directory.
In Azure Active Directory, select Roles and administrators (Preview) from the sidebar.
Enter Global administrator in the search field and then select the Global administrator role.
On the Global administrator | Assignments page, click Add assignments.
In the Add assignments pane that appears, search for the App Service and then click the tile for the service to select it.
Click Add.
...