@Kevin Azure Based on the error that you have shared it appears to be due to session control configuration in Conditional Access Policy.
If you navigate to Azure Portal > Azure Active Directory > Security > Conditional Access > Policies > Your_CA_Policy > Session, you can see the sign-in frequency configuration where you can configure time period before a user is asked to sign-in again when attempting to access a resource. The default setting is a rolling window of 90 days, i.e. users will be asked to re-authenticate on the first attempt to access a resource after being inactive on their machine for 90 days or longer. The value can be 1 -23 hours or 1-365 days.
Note: If you have multiple Conditional Access policies, you may consider using whatif tool under conditional access policy blade to narrow down the number of policies which are taking effect.
-----------------------------------------------------------------------------------------------------------
Please "Accept as answer" wherever the information provided helps you to help others in the community.