The working copiers are using one domain and the non-working are using another domain. I was able to determine that the domain that is working does NOT have Security Defaults turned on in Azure AD, while the non-working DOES has them turned on. The domain without the Security Defaults has a handful of accounts that have MFA disabled, including the one that is sending mail on the copiers' behalf. On the domain that has Security Defaults turned on, the per-user MFA settings don't appear to have any effect. I'm not going to spend any more time confirming this, but I read so many outdated instructions for this, I wanted to write down what I experienced here.