New accounts start with no access. You grant only what is needed - the security default of deny first, allow on purpose.
Sign in with the identity you already use
Connect your existing identity provider, so access here follows the same joiner-mover-leaver process as the rest of your stack. One set of credentials, one place to switch them off.