The already call IMAP an inscure, outdated service. So when you enable it, they will disable it for you after so many days whether you want them to or not.
For most services email is the master key to reset your password. By getting access to someone's email account a lot of other accounts can be breached easily. I try to disable password reset via email wherever possible. But most services don't provide this option.
I think it would be time for IMAP to get a standardized way to log in via OAuth2/OIDC. And maybe an update to the email standard to mark a recovery links or codes as secret, that require 2FA every time to read.
Especially dangerous are servers that still allow using IMAP without TLS, that's just asking for trouble.