This is what I’m running now and it works for me:
[auth.generic_oauth]
name = Azure AD
enabled = true
allow_sign_up = true
client_id = <client id>
client_secret = <client secret>
scopes = openid profile <URL to API permission configured in B2C>
auth_url = https://<your tenant>.b2clogin.com/<your tenant>.onmicrosoft.com/<sign_in_policy>/oauth2/v2.0/authorize
token_url = https://<your tenant>.b2clogin.com/<your tenant>.onmicrosoft.com/<sign_in_policy>/oauth2/v2.0/token
email_attribute_path = emails[0]