The resulting JWT is: Success! I also came across this post. This says that the “allatclaims” scope needs to be included but I got it working without doing that.
https://medium.com/the-new-control-plane/the-mystery-of-the-missing-adfs-jwt-claims-7658d9cdeaac



