VMware vCenter server 8.0.3 00700 (8.0 U3h build 25092719)
Previously, service accounts with MFA enabled were able to access vCenters without any MFA input if the vCenter had both a federation provider and a legacy provider servicing the same domain. This vulnerability has been patched out of vCenter as of 8.0 u3h, so failure is an expected behavior. MFA is now fully enforced on all accounts, service accounts included.