@Namless Shelter Apologies for the delayed response, to answer this statement - some ppl complaining that Windows Hello for Business they set up on their devices somehow allow them to connect GP VPN without giving MFA - Refer to this FAQ https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/faq#:~:text=Is%20Windows%20Hello%20for%20Business%20considered%20multifactor%20authentication%3F
If the user is configured for WHFB, Entra ID honors the MFA claim from WH4B sign-in.
Hope this clarifies, if not you can review the sign in logs to understand whether MFA was not performed or not - https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-reporting
Let me know if you have any further questions, feel free to post back.