To reduce your risks you could do what I've done for folks which is to just identify the MFA sites the moment they start sending traffic. I use a simple script to go check new sites that show up in the tracking and if they match the pattern for a MFA then block it pronto :-)
JAG