Azure AD SAML/OAuth log
At this point Azure AD doesn't provide a way to check log if SAML/OAuth authentication is getting failing due to some issue.
Last week SAML response was failing due to one of mapped attribute was blank on user profile. It took us 6 hrs to figure out by guessing what could be wrong. In most of other SSO product, you can check runtime server log and get reason in 5 mins!
Microsoft should provide some way to check server log.