@RST Thanks for reaching out. The federation for office 365 either by using ADFS or other 3rd party IDP such as ForgeRock would mean that the users will start getting redirect to ForgeRock for authentication.
The Azure AD will register the federation service (ForgeRock) so that it can redirect the user/device authentication requests to it.
All (Azure AD and Office 365)of the Auth request will redirect to ForgeRock as a result.
You can try this in a test tenant to see if it fits your need.
-----------------------------------------------------------------------------------------------------------------
If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community.