Security configuration requirements for all software-as-a-service applications are formally defined
The SaaS security configuration policy facet defines mandatory settings such as MFA and restricted sharing for every SaaS app, covering the SaaS side of A.5.23.
Defining the security settings every SaaS application must have, MFA, sharing defaults, admin limits, is A.8.9's configuration baseline extended to SaaS tools.