As the question states, we require that the user's Zitadel password be removed once the user is associated with an external IdP. We handle this on a user-per-user basis, so we cannot remove the login using username and password on the instance or org level. How can we prevent this user from having a password when they're associated with an external IdP? (This is a backdoor security risk).