What do you mean? The authenticator instance could ban users, the moderators and the content provider instances could ban users, content provider instances could defederate from authenticator instances and viceversa.
Not sure I'm seeing the issue you are seeing, it's just basically forcing lemmy instances to instead of being both to just be one or the other. The benefit is that the actions on one is free from the drama on the other. One would be dedicated to hosting users, the other would be dedicated to hosting communities, less burnout overall.
There's several solutions, I was just stating the "at least" solution because everything needed for it is already present. You just need to remove functionality depending on the type of service you want to host.