In addition to simple primary and second factor, you can design policies for MDM-controlled devices only (i.e. designing endpoints that are trusted for remote access), geolocation, and software versions on a per-application basis, for example.
I think save for a few use cases (SSH into your datacenter, e.g.), VPNs will be dead before we know it.