We recently let our SSL certs expire (I just moved into this role and hadn't checked them out yet). ADFS now has the certs, and is able to successfully connect to our CRM via the Relying Party Trust. When trying to login, it authenticates but then we get this error:

Looking for any guidance on what to check. I've ran through a bunch of learn.microsoft docs (which got me through setting up a bunch of stuff and got the trusts working etc) but I haven't been able to figure out this last part.
Thanks.