Cloud-based IAM solutions provide clear benefits for both the customers and the vendors. There is, however, the question of what happens if the cloud-based IAM solution becomes unavailable. This could be due to a number of reasons: IAM vendor has an outage or the connection between the customer to the cloud IAM is interrupted somehow (I'm looking at you, dragging ship anchor...). Any good disaster recovery plan must take complete or partial outages of not only internal but also 3rd party resources into account. Regulations like DORA or NIS2 not only mandate technical controls such as MFA but also require that the organisation is resilient against outages. Therefore e.g. the question "What happens if our Cloud MFA vendor becomes unavailable and how do we recover from that?" becomes VERY relevant. So.... what is your plan in case of an outage? You do have one besides "Wait and hope it'll be back soon"... right?