"Securing Azure AD is challenging"
I'd say securing it is close to impossible. With so many serious technical vulnerabilities lurking in that platform and an effective method put in place by M$ legal team to shift M$' blame away from them and put it fully on your shoulders, there is little hope you can make it secure. That task is too huge, you won't have the resources.