The subject identifier actual value is NAMESPACE_ID, so <NAMESPACE> is confusing. identity_token_audience has an audience value in Azure Federation, so examples like an existing vault URL are confusing.