...
Name for application, for example 'Benemen Authenticator'
Accounts in this organization only
Redirect URI is not needed : https://discover.beneservices.com
...
5. Go to Authentication tab and configure following
Select “Add a platform”
Select Web
Configure Web
Enter https://api.beneservices.com as RedirectURI
Select ID Tokens
Click Configure
Set Allow public client flow = Yes
Click Save
6. Go to Permissions tab
Make sure that app have User.Read permission
Click Grant admin consent and Yes to confirmation
Make sure that there is a green mark for Admin consent
...