
You cannot create Conditional Access Policies to enforce MFA based on first party applications (SharePoint, Teams, Outlook). However, there is a preview feature that lets you create sensitivity labels, assign them to sites, then put MFA to that site. Here is the preview feature that will let you require MFA to just SharePoint sites: https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=70594