There is the one trap-word. I am practicing a firewall-hygiene from the good-old ZoneAlarm days. If I don't need the software to 'get out', it is blocked. I only allow my Outlook to 'talk' to my mailbox carrier to bring in the emails. All other target IPs are blocked. So it can't 'phone home'. But again I'm on Office 2013 (and it still tries to phone-home).
For most services email is the master key to reset your password. By getting access to someone's email account a lot of other accounts can be breached easily. I try to disable password reset via email wherever possible. But most services don't provide this option.
I think it would be time for IMAP to get a standardized way to log in via OAuth2/OIDC. And maybe an update to the email standard to mark a recovery links or codes as secret, that require 2FA every time to read.
Especially dangerous are servers that still allow using IMAP without TLS, that's just asking for trouble.
Microsoft stores an OAuth2 access token for these accounts, which is still unnecessary compared to the locally synced version of Outlook we're all used to, but the user can revoke it through Google account settings at any time, just like any other OAuth2 access token.
Then they decided not anymore and replaced it with a bloated one...
So in a work environment it probably can never be used? I'm willing to bet that it won't make a single bit of difference.