* It’s much easier to do on-prem if you do a monolith, or at least a small number of services.
* You have to build and test your application against a range of OS and hardware combinations. You’ll almost certainly need to support RHEL, and probably Windows Server 20XX. Many companies won’t let you use Docker.
* Your software need to be tolerant of infrequent updates. Customers expect some level of stability in practice.
* You need to integrate licensing checks.
* You need to build an installer (that works out of the box…)
* You’ll need to agnostically support the common parts of SAML/OpenID for Auth only, and not rely on any bespoke features from a commercial provider like Auth0 or AzureAD.