Going to wage jihad on everything less than FIDO2/WebAuthn in any org where I'm affiliated; previously people were pushing for using push-auth shit (e.g. Microsoft Authenticator) as an option.
Previous jihads against hardcoded credentials (use Vault or equivalent).
Next target after this will probably be Slack.