Hello @Handian Sudianto .
Thank you for reaching out. I would like to confirm that Connect-AzAccount ideally authenticates user against all the tenants the id is part of. Hence when you enable MFA on the account user is forced to perform Interactive Auth. However, to support this you would need to specifically key-in the tenant id of the organization you want to sign-in to. This has also been documented on the following documentation: https://learn.microsoft.com/en-us/powershell/module/az.accounts/connect-azaccount?view=azps-10.2.0
An Interactive Auth example is listed as follows: Connect-AzAccount -TenantId contoso.onmicrosoft.com
I hope this helps and hence would request you to please "Accept the answer" if the information helped you. This will help us and others in the community as well.