This is definitely possible, and the way to do this is to have a multi-tenant Azure AD app registration with an "api" capability. This article will help get you started with Tab SSO, and shows how you can get the token you need. You can pass this token as a "bearer" tokens to your backend API, using the Authorization HTTP header, like this:
Bearer [token value] (so notice the word "Bearer" at the front, then a space, then your actual token).
These tokens are JWT tokens, so you can see what they look like by visiting a site like JWT.io, and pasting it into the text box - it will show the contents of the token on the right side, decoded.
On the backend, your API is able to verify these signed tokens, to ensure they are issued from your own Azure AD application, and to validate the user's AadOjectId, UPN, Tenant, and so on. This blog post shows how to do the actual token validation on the server. Validation ensures that the token is valid, and issued by your app, but it also includes a TenantId and the user's Azure AD Object ID, email address, and display name - everything you should need to securely identify the user and the tenant.
Incidentally, this applies to any front end, but works perfectly with a static react app in Azure storage (tested it to confirm).
[Update]: Microsoft just published an informative and up to date video walkthrough today on SSO. It doesn't fully cover your scenario (it doesn't validate the tokens on the backend), but it shows a lot of the preliminary steps nicely. See How to restrict access to Azure Function to only allow requests from a custom Microsoft Teams App?