What’s the difference? Their standards regarding MFA are in the link I posted. On page 5 it even talks about how implementing OOBA doesn’t seem effective as many customers will only have ability to OOBA with one device, their phone. And it’s not truly OOBA if they receive something like a one time password on their phone and then use it to authenticate on that same phone. This defeats the purpose of OOBA