Hello
Yes, it is possible to restrict 2FA authentication to go through the Microsoft Authenticator app published under a work profile only. This can be achieved by managing user consent to apps in Microsoft 365.
In the Microsoft 365 admin center, you can go to the Settings > Org settings > Services page, and then select User consent to apps. On the User consent to apps page, you can select the option to turn user consent on or off. This allows you to control which apps users can consent to and use.
However, it’s important to note that this might not completely block external authenticators like Google Authenticator or other authentication apps saved in phone or browser extensions. These settings are typically managed at the organization level and may require additional configuration or policy enforcement.