Hi anonymous userWescott-3367
You can Install Azure AD Connect in any server; the main requirement is that the host must have to be in the domain.
In Azure AD, it's obligatory to activate 2FA for administrator Accounts (of Azure and MS365), for the other users you can choose if you enable it or not.
You can use your 2008 R2 without a problem, the communication between the Domain Controller and Azure AD is the Azure AD Connect.
Hope this helps.
Regards,
Carlos Solís Salazar
----------
Please "Accept as Answer" and Upvote if any of the above helped so that, it can help others in the community looking for remediation for similar issues.