Thanks for posting your question in the Microsoft Q&A forum.
Joining Devices: You can join your devices to Azure Active Directory by going to Settings > Accounts > Access work or school and signing in with their Microsoft 365 credentials.
Configuring the VM: You need to ensure the Azure VM is Azure AD joined or Hybrid Azure AD joined, and assign the right roles, like Virtual Machine User Login.
Enabling RDP Authentication: In the Azure portal, we can go to the VM’s Identity section and enable System assigned
for Azure AD authentication.
I believe basic Microsoft 365 licenses should be enough for Azure AD join and authentication, but using Azure Bastion might have additional costs.
Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful