Two changes shipped this week, both about access rather than features.
Any user can now enroll in two-factor authentication from their profile: scan a QR code with an authenticator app, save a set of one-time recovery codes, and every sign-in afterward asks for a code in addition to the password. A system admin can require it for everyone, which forces enrollment on next login for anyone who hasn't set it up yet.
Separately, a system admin can restrict sign-in to a specific list of IP addresses or CIDR ranges, useful for teams that only connect through a known office network or VPN. Adding a restriction that would lock out your own current address asks for confirmation first, so this isn't a feature you can accidentally use to lock everyone out, including yourself.