At this stage, it’s just a circumstance of using the self assistance password reset operation for Okta or Entra (which you can get all over because you now provide the MFA issue to verify you) and voila, the attacker has taken control of the account. You're nonetheless proper that MX are necessary to slide back to the data, per RFC 974. This was