It would be really awesome if, when the ITDR recognizes a critical incident (and would normally disable a cloud only user) if it was able to identify if a domain controller exists in the same MDR tenant and pass through a powershell command to disable that user, and run a delta sync.