If anyone wants to "roll their own IdP" I wrote up a series of posts on how to create the necessary keys & config to allow you to login with a federated credential: https://finarne.wordpress.com/2024/07/25/acquire-an-entra-id-token-using-federated-credentials-part-1-oidc-discovery-documents/