I'm by no means an NTLM expert, but I would suggest starting with https://learn.microsoft.com/en-us/azure/active-directory/external-identities/hybrid-on-premises-to-cloud. I think synchronizing your on prem AD with Azure AD through Azure AD Connect should allow you to use the AAD provider. Since you're in the exploratory phase, https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/migrate-application-authentication-to-azure-active-directory is white paper that discuss this topic that may help provide some direction.
One you start trying things and run into issues, please do feel free to post those questions on Q&A.