I would love to see some improvements to authentication security.
Allow some sort of SSO via Oauth/OIDC to the common authentication providers (Microsoft Entra ID, Okta, etc.). This would allow us to enforce MFA, apply conditional access policies, and simplify user management. Also, one less password for users to remember.
Enable auto-provisioning of users based on groups and job titles within the authentication provider, streamlining new hire setup.
In the meantime, create a way for me to enforce MFA to all users via authentication app, not SMS. Currently all I can do check to see who set it up, remind them to do it, and keep bugging them until they do. I have no technical way to enforce our basic security policies.