Most Zero Trust write-ups stop at "user signs in, user gets access. " That's not where these integrations actually break. They break on group membership that almost, but doesn't quite, satisfy a policy.
Source: [Dev.to](https://dev.to/darkedges/proving-zero-trust-actually-works-entra-id-cloudflare-access-over-both-oidc-and-saml-4f7d)