I think the OIDC auth method would be a better fit for your use case.
Overview:
Azure AD specific settings:
https://www.vaultproject.io/docs/auth/jwt/oidc_providers#azure-active-directory-aad
Recent post about some configuration specifics that may be useful: