Thank you for posting this in Microsoft Q&A.
I understand that you are unable to edit the Multifactor Authentication policy for per-user multifactor authentication users in your tenant's conditional access policy.
To edit the policy, at least a Conditional Access Administrator role is required. Administrators have the ability to edit the state (On, Off, or Report-only) and the excluded identities (users, groups, and roles) in the policy. This policy targets licensed users with Microsoft Entra ID P1 and P2, where the security defaults policy is not enabled. Additionally, there are less than 500 per-user MFA enabled or enforced users. To apply this policy to more users, you need to duplicate it and change the assignments.
We are unable to edit the policy because it is Microsoft managed, as shown in the screenshot.
Using the Edit pencil at the top to modify the Microsoft-managed per-user multifactor authentication policy might result in a failed update error. To work around this issue, select Edit under the Excluded identities section of the policy. This will allow you to make changes to the policy without encountering the failed update error.
For your reference: https://learn.microsoft.com/en-us/entra/identity/conditional-access/managed-policies#multifactor-authentication-for-per-user-multifactor-authentication-users
Hope this helps. Do let us know if you any further queries.
Thanks,
Navya
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.