Fetches the avatar from Microsoft Graph using the access token when the standard OIDC picture claim is unavailable. Disabled by default. Requires the access token to have permission to read profile photos, such as Microsoft Graph delegated User.Read permission.