In this quickstart step we encourage spec authors to create a .env file with a client_id and client_secret defined. This is now disallowed by azure guidelines, so the entire scenario is broken.
We need to update oav so that it can recognize either user (eg azcli) or federated auth and leverage the credential in the api scenario codepaths.