Depends on what products you are using. Defender for cloud apps offers activity policies which you can use to configure such alerts. Another alternative would be to integrate the sign-in logs with Sentinel or a similar tool, and configure the alert therein, With "pure" O365 functionality best you can do is configure an activity alert, but those cannot be used with wildcards, so you will have to list each and every user.
how to get an alert of an unlicensed user if office365 authentication login
As you know, we change the display name of offboarded users to have a prefix of “zzz”. Eg. zzz John Smith Users with this name prefix should not normally log on to O365 or Azure Services.
Is it possible to set up an email Alert to my my mailbox and to our IT Mailbox to indicate when an account with this prefix successfully authenticates?
We'd like to have it as an extra “soft” measure against unexpected logon activity.