Hello @Takami Chiro ,
Thank you for posting here.
Here are the answers for your references.
Q: Do you know if Microsoft provide built-in MFA for domain sign on? Or I need to purchase a product to achieve it ?
A: Based on my knowledge, you are using on-premise Active Directory, there is no built-in MFA for domain sign on from Microsoft.
Q: IF the answer is latter...do you have any good product you are using?
A: Based on my knowledge, if you use Azure AD, Microsoft provide built-in MFA for domain sign on, for more information about Azure AD MFA, please refer to link below.
Secure access to resources with multifactor authentication
https://www.microsoft.com/en-us/security/business/identity-access-management/mfa-multi-factor-authentication
And if you want to know more information about Microsoft Azure AD MFA, please open a new post by selecting Azure Active Directory tag or Azure-ad-multi-factor-authentication tag.
And for on-premise Active Directory, if you want to know MFA, you can google in the internet and see if there is any third-part MFA.
Hope the information above is helpful.
Should you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.