Former Domain PC Tells You No on AzureAD
Apparently domain group policy has a thing that messes with the allowed users for logon. Many hours later, this one liner resets the logon and security settings in group policy to defaults. Once this is in place, magic. Everything works again.
secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose
Enjoy kids!