We hold ourselves to a higher security standard than most of our clients because we have access to many companies. Attackers have shown that MSPs are a huge target.
Internally we use Azure AD P2 features to manage ourselves and automate employee permission and application assignments.