Because Microsoft is too big to fail. When implementing MFA for BigCorps, their internal infra teams often only know MS products and refuse to accept that there could be a better alternative (even when 100% compatible with their stack). It's the ultimate vendor lock-in.
No, it’s because it’s free with Exchange, and also because this can’t happen (even if you screw up and lose access to all of your global administrator accounts somehow, you can contact Microsoft and prove you own the domain name to get back in).
IIRC it's not free for a wider identity deployment, it has incremental pricing that makes it look free. It works out somewhat cheaper than a third party solution.