there is a free training module provided by Microsoft
I offer you to follow at first to learn about conditional access policies
https://learn.microsoft.com/en-us/training/modules/plan-implement-administer-conditional-access/
Also Azure has another service called Azure Active Directory Privileged Identity Management (PIM) that can help you manage, control, and monitor access within your organization. It's especially useful when you have users who need temporary access to resources. To use PIM, you need to have Azure AD Premium P2 license. You can start PIM from Azure portal > Azure Active Directory > Identity governance > Privileged Identity Management. From there, you can manage Azure AD roles, and Azure resource roles, and view audit history among other options. I do not know your case but this service can also be helpful