Hi @Nick Branstein , have you tried to see if it works if you select Cloud Apps? You currently have "No Cloud Apps" selected. The CA policy is granting access for all the users in the group (after MFA), but the CA Policy isn't going to enforce MFA on sign-in to the Azure Portal, since you'd need to add the Microsoft Azure Management cloud app. Having no cloud apps selected also explains why if you turn on the CA policy, MFA is never enforced for any of the users in the group.
Please let me know if this helps!
Best,
James