Azure/Entra security product

We currently use Access Analyzer, Threat Prevention and Threat Manager. I’m trying to see what products might be available, either current or planned that would allow us to implement security within our Azure tenants. Ideally, something like Defender for Cloud but would be happy to start with something that, for instance, allows alerting/reporting on changes to Entra ID users, groups, applications, etc.

I do see in NTM, there are some very basic Entra related topics like Impossible travel and sensitive role changes. I believe that does require a separate license but would like to see an example of what that might look like.

Thanks!