Hello Glenn,
Thanks for your question.
Yes, you should be able to achieve this using conditional access for client apps. You can create policies that apply to specific client apps and enforce MFA when accessing through web-based clients
To do this create a conditional access policy and maybe limit to a couple of test users and use the link here to test before rolling out. See: https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-conditions
You can mark it 'Accept Answer' and 'Upvote' if this helped you
Regards,
Abiola