BYOC Edge 403 on SIP Registration with Multi-Tenant OAuth

Why does this setting prevent SIP registration on our BYOC Edge when using multi-tenant OAuth tokens? The edge logs show a 403 Forbidden on REGISTER requests.

“Ensure the OAuth client has the edge:manage scope and the edge certificate matches the tenant’s public key.”

The scope is present, but the token validation fails specifically during the TLS handshake phase.