We currently have SSO enabled for all of our domain users. We exempted our MSP from signing in via SSO but wanted to enforce 2FA. It seems like when we enable 2FA it affects everyone, even people who authenticate with SSO. Our domain users already have to go through a MFA prompt to get into Okta, having another 2FA prompt to get into Hudu feels a bit overkill.