This was a case of my expectations being different than the product's UX. The first pass-through of the UX it goes to the "Complete Sign Up" page. Which I'd assumed was not the expected behaviour. During the SSO configuration I had also added the Token Configuration to the auto-configured app-registration.
Namely, the claims added to the id_token are (as per step #17):
- family_name
- given_name
in the App Registration so the claim should have that info to pre-populate and create the user on the api-management side. This does seem like a product bug that it requires completing the sign-up in light of fully-populated Entra ID users however, it's nice to see it works.