Put captive portal in place and force the users to validate through their phone numbers, social media accounts or emails. You can even integrate your existing IdP to the captive portal and even ask your employees to connect through the captive portal.
I've now taken my hindsight glasses off and recognize that it's hard to imagine that assholes and criminals would so easily ruin it for the rest of us. 50+ years later and ~30 years later of the interwebs and now it's an "but of course they would". The sad thing is that there should no longer be a blank sheet of paper for a startup, but every "new" sheet should already have defensive strategies on it. It's just not sexy, and hard to get to MVP so it's easy to drop/ignore/delay. I'm guilty too, but maybe I'm worse because I'm well aware that I'm doing it????
You can still argue about the endpoint security, but at least the network participants and their messages can be secured, even if an endpoint is compromised.