Just to be clear, per-user MFA is not going away, you can still use it if that's your preferred solution. As for checking CA policies coverage with regards to MFA, you can use these workbooks:
https://learn.microsoft.com/en-us/entra/identity/monitoring-health/workbook-mfa-gaps
If you don't have Log analytics, work with the User registration report instead: https://portal.azure.com/#view/Microsoft_AAD_IAM/AuthenticationMethodsMenuBlade/~/UserRegistrationDetails