Vault auth users with Azure AD

I am new to Vault and I am pretty sure that I don’t fully understand how this should work. My Vault instance is running in AWS (like the rest of environment). What I’d like to achieve are Vault users authenticated using Azure AD without creating them in userpass method. So each user could login to Vault using his token obtained from Azure AD. Is it possible to configure it in that way? I can’t find any example. How Vault Agent config would look like in this case?

I think this is a duplicate of!topic/vault-tool/Er30IInJMeU
