Hello,
I am unaware of such a setting and I am questioning if that is a good suggestion. CRL checking is part of standard security measures, so we should leave it enabled. You mention that other users do not have this issue.
Therefore, I looked up telemetry based on code flow and I think now the error is misleading. AL is not smart enough to through the correct error and therefore AL thinks the error is related to the SSL cert.
It is very likely that the user is having an issue. The user's account is either disabled or not configured correctly in AAD. We may also receive this error when this issue happens related to the token:
A security token was received that is associated with an unknown or disabled user account in Azure Active Directory.
Could you please verify the user that does not have the issue and compare it with the user that does have the issue? In AL you can also clear credential cache, etc.
Hope it helps. Otherwise, raise this as an issue to Microsoft so we can really look up the telemetry or error logs for your Sandbox tenant.
Thank you.