Hi peter,
Please follow the below OIDC SSO documentation to get roles in access token
https://docs.mendix.com/appstore/modules/oidc/#azure-portal
ex:api://d99a49b9-95d7-410e-b79a-54ede8968065/8dd52bfa-6d7e-453b-b506-303c0a3d9567
The above example scope can be found in Expose an API