@stefan-0 I don't really see where there is an issue here, we wouldn't want to actually keep the Azure AD access_token if you want it just add something to the openid reconcile lambda and store it as needed.
https://fusionauth.io/docs/extend/code/lambdas/openid-connect-response-reconcile