This is a bit of an interesting take from: https://www.migadu.com/procon/
"We could enable 2FA on the webmail, but IMAP/POP/SMTP accesses remain unprotected which beats the purpose. We are working on solution here which will allow sand-boxing a username/password pair to a webmail use only."
That's an incredibly misguided sentiment