"App Access Control setup so users can create accounts using oAuth ONLY for services we have approved"
That is actually the most important step anyone can take.
Sign up/in with email - is completely out of your control, since most organisations don't block incoming email for staff, which is usually necessary to verify the email and activate the third-party account.
On the part of accounts costing someone something, as soon as you are made aware, it is possible to do a password reset of the third-party account, sign in and cancel it. Since it's just an email address, you don't even have to create an account. You can just add it as an alias or group, and receive the emailed reset-link to your own inbox.
The prevent action is to, of course, educate your users before they make such mistakes, and also very clearly state in the offboarding instructions that such accounts must be cancelled by the user themselves, preferable well in advance of their last day at work.
--
https://wheretofind.me/@NoSubstitute