Most Zero Trust write-ups stop at "user signs in, user gets access." That's not

where these integrations actually break. They break on group membership that

almost, but doesn't quite, satisfy a policy. They break on admin consent that

was never granted, silently, until the first real sign-in. They break on the

one country rule that was supposed to be an OR and was actually an AND.