A cloud-based identity and access management service for securing user authentication and resource access
You can use the Azure AD audit logs data for that: https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/concept-audit-logs
You can export them to an event hub/integrate with SIEMs: https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor-stream-logs-to-event-hub