Best Practice & Roll Out - Option 1
The first and more common approach is to enable only modern authentication and see what breaks on the Client
Modern Authentication: Enabled
Roll-Out
Some steps to consider:
Consult with the client on the security risks and need for Legacy Authentication.
Enable
Train Level 1 MSP support teams on Modern Authentication and if the client's applications stop functioning after this change how they can help the client understand the risk and potentially identify an alternative
If Legacy Authentication must be used, then chose the Option 2 approach next