We are required to use MFA by SUNY security guidelines. Our systems are under constant attack. The most common are password spray attacks, where attackers send thousands of logins using usernames and passwords harvested from the web, and phishing attacks, where attackers attempt to get your username and password. Multi-factor Authentication stops all these attacks.
Suppose you would like a detailed analysis of how MFA protects logins. In that case, Your Pa$$word Doesn't Matter lays out Microsoft's research across millions of logins, explaining why passwords are insecure and how MFA results in protecting against all but the most targeted attacks.