Only seeing one idp group in selector list

I am trying to get ZTNA properly configured by assigning users to Azure groups and allowing access to applications based on Azure groups.

I am only able to see one Azure security group in the selector.

I have Support groups set to Enabled in Settings>Authentication>Login Methods>Azure AD, and I have added Group.Read.All to the Enterprise App permissions in Azure Ad and granted admin consent.

Am I just impatient and Cloudflare will sync with AAD in a few hours/overnight? Can I trigger a manual sync?

Have I missed something?