Hi
I tried with two accounts and two different Entra applications.
The first one was without MFA and previously used by the registered application and API permission was granted. Yes, it gives all consent granted before even if permission was deleted.
The second account has not been used before by a registered application(same app as 1st) and the token does not contain extra scopes.
The third test case was a new application on Entra with an account without MFA. When I tried to get the token "openid" scope(which by default was granted) it required admin consent to use this application.
Overall, I can say that it might be a cache or misconfiguration. You can try later will it permits you even after deletion or admin consent for this application should be revoked.