Well how are synchronizing the users to Azure AD, if at all? Hybrid generally means you are using directory synchronization (password sync and other features are not required), thus the need for AAD Connect. You dont technically need it to enable MFA for objects that already exist in Azure AD, either created as cloud-only or synced.
Azure AD Connect required?

Wil
21
Reputation points
Verbiage on the below link seems to imply Azure AD Connect is a requirement (prerequisite) to enable MFA in Azure AD if using "Hybrid identity scenarios". We use AD DS on-premises and Azure AD for Microsoft 365 resources. We want to continue in the same configuration (separate passwords, not synced), and enable MFA for Azure AD. What are the pitfalls of enabling MFA and bypassing Azure AD Connect?