The thing with federation is if that is the kind of thing you are dealing with then it is up to the instance that had lax signup to clean up their own mess.
If this did happen and the admins of the offending instance said they were dealing with it then I would be happy to give them some slack to do so, and would probably offer any assistance I could.
That said, it is still very much their responsibility to handle it, or they risk their instance being blacklisted.
Microsoft aren’t exactly big on implementing “the latest” stuff. Not at a keyboard currently but I’d be willing to bet GH doesn’t support TLS1.3 either.