Hi DanT, the article shared by gavin12345 does not show that these security changes are a decision made by someone at MYOB.
They are definitely an ATO requirement.
However the article does claim that the changes being for all customers instead of only those using payroll is a result of a previous decision (2 years ago) from MYOB to have STP reporting online.
Whether their claim is true or not, I can only see that the solution would then have been a login to the software, with an additional login + 2Fa + inactivity for the payroll workflow. Segregating the software by workflow would in my opinion be a far worse experience