You see to assign it an Entra ID role to the Service Principal using PIM (such as Teams Admin Built-In Role). Documented in step 5 of their doc.
You can also see full setup here