AOS loads AAD signing certificates during startup and doesn't refresh them afterwards. As a result, AOS stops trusting any authentication tokens when AAD switches to signing certificates that were not known when AOS started, and no users can login to AX.
This issue can be worked around by restarting all the AOS instances.