It is my understanding that when a user leaves the company and their Microsoft Sign-in account is deactivated, the device will still have Wi-Fi access until the certificate expires. This is because authentication is based on the certificate installed on the device, not the current status of the user's account.
I believe that one option to revoke access immediately is to manually revoke the certificate in the Meraki Dashboard. This will prevent the device from authenticating to the network, even if the certificate is still valid.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.