Thanks for posting your question in the Microsoft Q&A forum.
Since the AAD DS domain is "ds.domain.org," users should use the UPN format "@ds.domain.org" to log in successfully. Using "@domain.com" won't work because it doesn't match the AAD DS domain.
You can consider setting up a custom domain in Azure AD that matches your AAD DS domain ("ds.domain.org") to allow users to log in with the format they are familiar with ("******@domain.com").
** Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful **