I think I managed to solve it 😄
Setting the appsetting
{ name: 'WEBSITE_AUTH_AAD_ALLOWED_TENANTS' value: tenant().tenantId }
seems to have ticked the "Allow requests only from the issuer tenant"