
Depends on what products you are using. Defender for cloud apps offers activity policies which you can use to configure such alerts. Another alternative would be to integrate the sign-in logs with Sentinel or a similar tool, and configure the alert therein, With "pure" O365 functionality best you can do is configure an activity alert, but those cannot be used with wildcards, so you will have to list each and every user.