Simple. Your users don’t care if it’s insecure. They click on fake password reset emails. You’re the bad guy here. They still haven’t forgiven you for requiring them to enter numbers when they want to log in.
Just say your cybersecurity insurance will not cover damages caused as result of inclusion of applications that are not compliant with the policy, loop in legal, sit back and watch how quickly bricks are shat.