With MFA a password alone is not enough to sign in: a second "factor" is required — a code from an app, a confirmation on your phone or a physical security key.
If a password ends up with an attacker through phishing or a data leak, MFA is often exactly the barrier that stops the account from being taken over. The most important places to enable it are email, administrator accounts, VPN and financial systems.
An employee's password was entered on a phishing site, but the attacker couldn't get into the mailbox — the code only went to the employee's phone.