That's cool. I recently built MFA into the access flow, with a sight to extend methods where needed, although any instance using the SAML/LDAP/OIDC auth options could enforce MFA on the identity provider side.
I apologize but may I know what you mean by "saas pass"?