We only use SSO for the majority of our systems, we still get people falling for phishing login forms that look like they were created in Word 1997.
There is a plan to use MFA for staff with higher access but trying to get that working for every single staff member with an IT account will be mayhem when they forget their phone or lose their yubikey...
Classic example of the triangle of security, ease of use, speed. Only ever 2 of the three when people just want all 3. And that is why JISC saw 100%
Very few are willing to do security properly all the time as it takes a lot of effort