point 3 is only true for G Suite customers - if someone is on O365 and signs up for Google normally with their company account, they can access that email after their company turns off access to the email unless they also specifically reset the Google password.

To be fair - you end up with G Suite, Okta or O365 endpoints for B2B. Apple isn't even on the radar there.

