Forgive the naive question, but would 2FA completely mitigate this attack, assuming that the org trying to access a key vault did not have access to the 2FA device?
Doesn't this hark back to "If the attacker has local access, it's already game over"?