MFA existed, on the firewall. The application said privileged access. The policy was unwound from the first day, a month after the ransomware.