Setting up OpenID IDP with Azure AD: error "access_denied", "unexpected iss value


I am setting up an enterprise connection to an Azure AD OpenID app registration that is MULTITENANT, that is, its using “common” everywhere a single tenant application would use its tenant id basically (like in the token and authorize url for example).

I have this in the connection configuration:
Issuer URL: https://
Issuer: https://
Authorization Endpoint: https://
JWKS URL: https://
client id: the azure app client id
type front channel

I tried back channel and providing the secret but I get the same error when testing the connection:

  "error": "access_denied",
  "error_description": "unexpected iss value, expected, got:"