Thank you for asking this question on the Microsoft Q&A Platform.
An option, that can help you is using an Azure AD Application Proxy
With this architecture, you will require an Application Proxy connector, this server will need access to some specific URLs in ports 80 and 443, but your app will be with no internet connection
Hope this helps!
Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.
NOTE: To answer you as quickly as possible, please mention me in your reply.