Since partners had to change to AzureAD Conditional Access, and more and more customers are enforcing MFA, for example the deployment of packages using Azure DevOps CI/CD pipelines is getting more challenging and also since the tools provided through LCS API still needs a username and password in most cases. But all the admin users, or users that have been added in the past, some customers just don't want to allow external email addresses to be added to the LCS project (with the trouble which comes with that).

In some cases, and since the access through LCS to data or other parts of the application can be called "High Privileged" I would say, having the ability to control the access through conditional access would help a lot (for example, based on location).
