MFA -> this seems like a no-brainer to have out of the box.
SSO -> if we're talking SAML and "mega corp looking to put everybody sync'd to their Active Directory" then it seems kind of reasonable. In part I think that the pain of employee onboarding/offboarding is just much more at larger corps.