The only way I can see this being resolved, but not optimally is as follows:
In the relyingParty
section, add the aud
claim yourself with a defaultValue
.
xml
<OutputClaim ClaimTypeReferenceId="aud" DefaultValue="applicationID OUR_CUSTOM_ID" AlwaysUseDefaultValue="true"/>
Downside is that the Relying party is fixed regardless of the clientId used in the auth request.