I have an employee who gets this error. However this is only on her own PC - If she changes to another PC she can log in and it works so I guess it's machine-wise, anyone got some suggestions?
I had the same problem recently. Like your situation, I have exactly the same URL in my application and in Azure AD, but still have the "AADSTS50011 error".
Finally, this error message is nonsense. I add the following configuration to allow the Azure Application to read all types of user groupe and resolved the problem. (Azure AD application > Token Configuration > add groupes claim):