We've done it a couple ways now. First was configuring Azure AD and using Azure AD Domain Services to network all our Azure VM's. Once you have Azure VM's configured with Azure AD Domain services then hooking up AGS Manager security configuration (Integrated Windows, LDAP, etc) to them is no different than on-premise. The configuration in Azure portal can be a bit confusing since some settings are only available on the old azure portal (https://manage.windowsazure.com/ vs https://portal.azure.com), so you sometimes need to jump between the two and that is really confusing if you don't know the old portal exists.
We've also recently configured Portal/ArcGIS Server with Azure AD using SAML. For this you need to configure an application in your Azure AD account. Once you create the app, you will use the URL and ID's that Azure provides to do your setup in Portal. Unfortunately if you need to modify the SAML token attributes that Azure AD emits the only way that I have found to do this is to upgrade to Azure AD Premium service. Esri has provided a custom app configuration template in the Azure Marketplace for free, but it only works for ArcGIS Online, not Portal. I've submitted a request for Esri to modify the template to not limit it to only AGOL since it appears to just be some validation that forces you to have an arcgis.com domain, otherwise its the exact same configuration I created manually but had to pay $6/user/month for premium Azure AD to do it.
Sorry, I realize this is a bit rambly with little concrete instructions. If you try it out and get stuck, feel free to reach out and I am happy to try and help.