shanecentre
You need to get a token as the email itself, not a global admin or any other account. You can add something to the scopes and submit the popup to invalidate the current token. Then go back to the system, remove what you added, submit the popup again, and when you get redirected to MS login as the email you are trying to configure in the helpdesk. Once you do this it should authenticate successfully.
Cheers.