Id.Web offers 2 FIC credentials - FIC + MSI and FIC + OIDC. In both cases, the audience of the credential is tied to the cloud where the credential is used.
For example "api://azureAdTokenExchangeUrl" for public cloud, "api://AzureADTokenExchangeUSGov" for UsGov sovereign cloud etc.
See a more complex example below - the "tokenExchangeUrl" in the CredentialDescription is tied to the Config section of MicrosoftIdentityApplicationOptions associated with the credential.
For a complete solution, 1p SDK should inject data about clouds that are not public.