This might be a stupid question but I am confused by the ambiguity of the additional context and push notifications for Azure MFA.
In the Basics Tab for Microsoft Authenticator (under AAD > Security > Authentication Methods), if we limit the scope to some users and groups, and then in the Configure Tab if we leave the additional contexts as Enabled for all users -> does the target user still remain the ones we selected in the Basics tab or is the additional context push notification enabled for everyone?

