If admin login is using weak credentials, it is by definition not a secure backend. Password/credential management and mandatory MFA are ALWAYS part of security due diligence for suppliers.
The work flow we used was AWS Vault -> Okta -> short lived AWS creds.
https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p...
It briefly pops you out to a browser to authenticate and caches a short lived token locally
There's tools like aws-okta that can advantage of that to supply short lived credentials which require 2FA
You could also write a service that requires whatever authentication you want and returns the results of STS AssumeRole