After creating the app in AAD, give the process 30m. Apparently, it has to sync up with an ACS instance, and that now works (fastish). Azure [paid] support helped me figure the underling issue, in my words, that occurs when no sync has occurred. This means that the idp/issuer value of the AAD-side record is missing. Or something like that – and about which I really don’t need to know about assuming it “just works”.