I once worked at a company where I had to logon to the corporate VPN with an MFA token, then logon to the datacenter VPN with a second token, then logon to a VMWare Horizon virtual desktop and then RDP to a VM inside a tenant network. I needed a different AD cred for every tenant.
treat your employees like cattle; see how far that will go