I figured it out; needed to pass the “audience” param in the silent authentication request, as well as the openid scope.
openid