As discussed offline,
It depends on RDP solution. If RD gateway sends an authentication request to NPS it has to perform MFA.
You will have to check with RDS or NPS side if there is any device specific policy can be triggered.
For now, this feature is not available in any of the settings that can be configured from Azure side. However, you can provide your feedback regarding this in our Azure feedback portal below,
https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.