Please advise if it’s possible to track mac addresses of specific ports/switches, and generate an alert if any new mac address added which isn’t part of the list I defined?

If you want to maintain a list then yes, you can basically create an alert rule which checks for a mac address not in your list.

Take a look in the tables for the data you need and start to build a rule up. We can help you once you’ve put in some ground work

Can we use this same method to be alerted if a stolen device comes back on our network?

If you are checking for a specific mac address(es) then yes.

There is an example in the docs under Alerting → Rules

Got it m thanks