Every row ends in a residual risk, because a failure-mode table with an empty last column has not been finished.
Row one is the honest one: this architecture cannot survive a total identity-provider outage, and no design on Azure can. Applications tolerate it for up to one token lifetime and no longer.
Availability strategy is therefore graceful degradation, not an alternative identity provider. A second IdP would double the attack surface to remove a failure whose measured frequency does not justify it.
The three that need decisions
170 service principals holding secrets. Needs a funded burn-down with target dates, or an explicit acceptance with a named owner.
Tier 1 privileged roles require only one approver. Raising it to two costs activation latency; the trade is the client's to make.
Leaver removal can lag up to six hours behind an HR feed outage. Emergency terminations use a manual runbook, which is a process dependency rather than a control.
Where the review should push
Layer 3 authorization lives in application code the platform does not own. The shared library and contract tests reduce but do not remove that exposure.
Cross-tenant reporting and the shared authorization library are the two components whose compromise affects every tenant simultaneously.
Dynamic group evaluation lag during a large reorganisation is an availability-of-access problem that is invisible until it happens at 40,000-user scale.