I worked on a service request where our customer faced a connectivity issue using Active Directory- Universal with MFA authentication. After our basic troubleshooting we're used to suggest taking a network and https traces in order to review the communication between the Application, Azure Active Directory and Database server.
I found a very useful option in SQL Server Management Studio that you could create an ADAL tracing that is available beginning with SQL Server Management Studio SMS 17.3. Off by default, you can turn on ADAL tracing by using the Tools, Options menu, under Azure Services, Azure Cloud, ADAL Output Window Trace Level, followed by enabling Output in the View menu. The traces are available in the output window when selecting Azure Active Directory option.
Very nice option when we have this type of problem.