Organizations that are serious about security should not allow random OAuth apps. Both G Suite and O365 admins can restrict what OAuth apps are allowed.
My wish would be for some sort of multi-person approval process rather than allowing anyone who is an admin to authorize an app. Even admins can be susceptible to a targeted and advanced attack.
Also, many people (like myself before my own “failure”) simply aren’t aware of OAuth apps as a serious attack vector. Most remedial training around phishing campaigns covers things like fake login pages but not “An attacker has spoofed an internal domain and an OAuth app with your company’s name in it”.