+1. This is an essential feature. One of the target markets (unless I have misunderstood) is for MSPs that will use it with multiple SMB clients.
The current security model has one shared admin account (not great) for the MSP across all sites with no MFA support. A compromised credential exposes management of all client sites. As an MSP, this alone will prevent us from deploying InstantOn as a solution, which is unfortunate as I think it has some good potential (with a bit more work).
I find it strange that the offering has actually be released this way with so little regard for security.