Hi Jennifer,
Thank you for contacting the community forums.
You can exclude the users IP range from the Conditional access policy if you their IP will be be constant. Or you can exclude the country.
Another option you may consider is to exclude by device filtering.
You have various properties you can exclude by.
Trust Type: azure ad joined, registered, hybrid,
DeviceID
Device ownership
etc...
In regards to securing the users account. you can enforce MFA via CA policy and perhaps consider bitlocker encryption for the device.
https://learn.microsoft.com/en-us/mem/intune/protect/encrypt-devices
Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.