I see the "How One Bad Password Ended a 158-Year-Old Business" story has resurfaced (as a thinly-disguised SpecOps ad).
If a single non-MFA'd password is an existential threat to your entire enterprise ... maybe the problem isn't the intern.
And maybe the fix isn't a single vendor.