Hello @Rafik ,
Thanks for reaching out and apologies for any inconvenience caused by this issue.
Here are my thoughts on this scenario:
If there are more than one CA policy applied for same set of application due to which MFA might have repeated which resulted multiple time MFA for user. Example: the current implementation has Teams requiring MFA within 1 days and when a user launches Teams they are prompted. While inside of Teams, another MS service is called (sharepoint for example) and another conditional access policy will prompt for MFA for SharePoint.
This continues for each accessed MS application and conditional access policy that is configured. This article has more info on service dependencies to help identify which apps will need to be included on your conditional access policy: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/service-dependencies
Secondly, if the token is getting invalidated by application lets say MS Teams inactivated token due to some reason then user may asked redo authentication including second factor authentication based on CA condition but getting MFA prompts in the middle of Teams meeting which seems to be problematic.
Therefore, this would require active troubleshooting to identity actual cause for the issue hence I would recommend to you reach out to MS support who can help you. In case if you don't have support plan then I can help you with One-Time free support.
Hope this helps.