@Machist • Thank you for reaching out.
M365 doesn't use its own AD, all the users and groups that you create and manage via the M365 portal are actually stored in Azure AD. So there is no need to sync or create separate Azure AD tenant. If you sign-in to the Azure Portal with your M365 user account and navigate to Azure AD > Users, you will see all the M365 users listed there.
To get access to Azure servers, VPN etc., you need at least Reader access on the Azure subscription. You can also use other roles on the subscription such as contributor, owner and so on, depending on what level of access you need. You might need to reach out to the owner of the Azure subscription to grant you access to the subscription if you don't already have the owner access to the subscription.
-----------------------------------------------------------------------------------------------------------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.