Authentication with Azure AD if Azure is not allowed by the FW

this is my first port and I hope I get support from you.
short question, is it possible to authenticate with Azure although Azure is blocked by the firewalls?
I read that Zscaler connects directly to O365 and so the MPLS is thus avoided.

any help please?

Authentication will happen only if the user able to reach your idp.