Do you have the option to create a mail alias for that user? That is what we do when people already created an AppleID using their email address.
Are you using Federated Authentication? If so, the user will be informed that you own that domain, and they will be asked to change their Apple ID:
How Apple notifies users whose Apple ID conflicts with Apple School Manager
If you're on Apple Business Manager, or not yet using Federated Authentication, you might just try informing them that it is in their best interest to change the email address associated with their personal Apple ID to their personal email address. Since you control the email domain, it is technically possible for a bad actor at your organization to take control of the email address, and therefore their personal Apple ID.
You can also give them this resource: Change your Apple ID
We have the same problem.
Our employee did changed the primary e-mail address for his account.
But the work address still cannot be used to create a managed Apple ID.
Is there some fixed period for which the same address cannot be used? I did not find any.