> You’re going to sign up for Okta or Google Cloud Identity, tie as many of your applications (first- and third-party) into it, and force 2FA.
Are these really the only options? I'm not terribly comfortable with an external entity owning my SSO--ESPECIALLY Google.