Hello @MTawfik ,
Perhaps I missed the point of your question, my apologies I have reviewed it now.
That's not possible, when a user signs in to a particular service, his/her identity must be checked against the identity provider this is done through login.microsoftonline.com
​So the AAD service principal (app registration) is required to sign in the user and validate the user, AAD will provide an authorization token to the user and the user will use the token to authorize his/her request to the API scoped in the app registration.
Based on that I would say you can't achieve what you are looking for.