This is a new "feature" of LMI Central that even the support people at LogMeIn have NO IDEA about when we first called about it a few weeks ago. After being blown off for months with support we finally managed to escalate this to a developer who confirmed the "features" but refused to remove them from our account.
Basically what happens is LogMeIn determines that someone at your company (regardless of MFA settings) appears be compromised, in our case from users entering their own password incorrectly a few times and locking the account.
Then what happens, no matter what the MFA policies state, LogMeIn will NOT provide access to these users until they access the email account on file to put in the special security feature code that LogMeIn silently implimented for it's customers. This is a MAJOR issue for us because our users do NOT have remote access to their email accounts for security purposes. We have ALL users on our accounts setup for MFA which should send their cell phones a login code however that is completely BYPASSED and the code is first sent to their email and then to their phones. This "feature" is completely wreaking havoc in our enviornment due to limited email capabilities of users until AFTER they are logged in with LMI.
Between this "feature" and LogMeIn deciding that they are going to randomly push Kaspersky on corporate owned computers without warning and even though we have an antivirus solution we feel that the company can no longer be trusted to be transparent about their intent or policies. We understand the need for security, hence the reason our users don't have access to email externally, however there is NO communication from LogMeIn on these things and most of it's done under the radar without their own support folks knowing about it. We don't have a small account, we will be moving ALL of our products (LMI, Remote Support, JoinMe, etc.) to another company. Trying to get someone at LMI who cares is a worthless endeavor.