I agree from a roaming user perspectiv, but I presume most O365 installation would run on a static wan ip-adress so I don't see any enhanced security by using modern authentication as long as our firewalls only allow traffic from the Ofifice 365 official Wan ip adresses for retreiving the data.
allowing your firewalls to only connect to the official office 365 wan ip doesn't prevent attackers from brute-forcing passwords and trying them out on their side. That's the real reason why you'd use 2FA/MFA.