@Michael O'Hara
Thank you for your post!
When it comes to the different Azure AD MFA user states (Enabled/Enforced), the table below provides a great depiction of the three states:
When you enroll users in per-user MFA, their state changes to Enabled. When enabled users sign in, and complete the registration process, their state changes to Enforced.
Based off the table, if a user in your org is using a browser app, they'll be required to register for MFA after the session expires. Additionally, you can also reference the Azure AD Sing-in Logs and filter for Multifactor authentication.
Additional Link:
Authentication Methods Activity - The new authentication methods activity dashboard enables admins to monitor authentication method registration and usage across their organization.
I hope this helps!
If you have any other questions, please let me know.
Thank you for your time and patience throughout this issue.