Framing MFA as "someone had this factor at this moment" is the right correction, because it says nothing about the session token that lives for hours afterward. Most account takeovers I read about now skip the prompt entirely: token theft, push fatigue approvals, or a helpdesk reset that re-enrolls a new factor. Phishing-resistant factors like passkeys close the first gap, but recovery and re-enrollment stay the soft spot. Which control do you think gets the most underinvestment: session binding, or verification at the helpdesk reset step?
iin1005h0728