Could you do something like self hosting a MDM (say Fleet?) so you can kick the tainted Apple ID off your devices and get them back if this happens?