If the account user principal name is in your primary domain FQDN format (ex. user@contoso.com), then change it to the Microsoft Domain Fallback. For example:
Once you change the user principal name of the account in the Azure Portal, then go to your ER Credential Manager and add the account credential using the MS fallback domain format.
Now, you should be able to create your Azure AD discovery and add the account it should now show as authenticated.