Right now it is up to the individual users or the admin of their license server to enforce multi-factor authentication on AutoDesk IDs. The security requirements at my company call for us to enforce multi-factor authentication to be able to use the Vault Gateway to allow external access to our Vault Server. Since we are not in control of the license servers of the external companies we work with we are not able to enforce MFA for users connecting to the Vault Gateway that do not work at our company.