As an example, my employer requires 2FA on pretty much everything, so the start of my day looks like:
* Power on laptop, log in using laptop password
* Log in to LastPass, use lastpass password, verify with 2FA.
* Connect to VPN, log in using SSO (Okta) password from LastPass, verify with 2FA.
* Open github tab, log in using the Okta password again, verify again with 2FA.
* Open JIRA ticket, get sent to Okta, skips password prompt since already logged in, verify again with 2FA.
* Open email, get sent to Okta, skips password prompt, verify again with 2FA.
* Oh, my calendar tab was already open so Google didn't know I authenticated in another tab so sends me to Okta which now expects another 2FA there once I interact with it.
Also the policy is that the lastpass password, SSO password and laptop password should be different. So that's 3 passwords and 5 2FA pushes in about 5 minutes (and again after lunch as all those sessions expire during it).
My understanding is you can configure Okta to remember 2FA on a device for a while, but our security department has chosen to disable that. This is a lot of security overhead, but in this case I'm being paid for it rather than paying for it so whatever. Can you imagine getting a paying customer to agree to this level of 2FA double checking?