AFAIK this is not currently possible. I’d also like to see functionality added to disable the standard authentication to the web client when SSO is enabled - even simply removing the username and password fields from the login page would be a welcomed change. I have set up SSO and the workaround I have implemented is reset all user’s web client passwords and not provide them with the new one. I have also edited the welcome email template to remove the code that would include the password in the email and added text to inform users to click the Google/M365 button to sign in. This way new users are unaware of what the password is and the user can’t obtain the password with the “resend credentials” function.
The passwords 3CX generates are complex enough that they wouldn’t be susceptible to dictionary attacks, brute force, password spraying, or showing up in databases of compromised passwords. With the right security settings for blacklisting an attacker’s IP would be blocked almost immediately and for ~31 years! This is the closest you’re going to get, currently, to effectively disabling standard authentication.