App Roles would allow us to integrate the level of privilege that a user is authenticated to Hudu with. Allowing a user to log in normally with Author or Editor rights, and then use Azure AD PIM externally to elevate into an Administrator Role within Hudu just in time by moving into a Azure AD Group with the super admin role assigned.
https://learn.microsoft.com/en-us/azure/architecture/multitenant-identity/app-roles