Also, where the hell were your backups, why didn't they follow 3-2-1.
Also, where the hell were your backups, why didn't they follow 3-2-1.
For RDP it's even easier, RDP is easily configured so that logging in and connecting are two different distinct actions, after connecting you are presented with a login page. If that system is tied to a Windows AD domain, you can enforce MFA via numerous different methods, although unfortunately it's not possible to use Windows Hello over RDP currently (meaning no support for passkeys or biometrics as a second factor). I've used systems in the recent past that enforced smartcard control for RDP access.
The fact that most organizations /don't/ do this isn't due to any technical limitations, it's mostly due to not prioritizing information security at leadership levels combined with an InfoSec industry culture that centers more around box-checking by midwits who have certifications than designing secure systems from first principles within your technical constraints by actual experts.
Now, what is even more concerning is if they didn't have the ability to 2FA on their Citrix, they had to be running a massively old and insecure version.