MMH now prompted me for a password change. It didn't prompt me for the configured MFA TOTP code, but rather sent a code by email.
When using a passphrase tweaked to meet their 'strength' requirements it failed. After meeting all the criteria in the first so many characters the check passed (otherwise same passphrase).
Now I can't log in any more. Sounds like some client side security theatre with password truncation that will then fail on an actual log in on the front door.
