I found a fairly simple solution (which worked for our purposes):
I simply opened the https://login.microsoftonline.com/..etc.. URL in a new browser tab. No more CORS error, because now there is no 'origin' :)