Another policy using this concept with Filter for devices to only target devices/users that should be able to meet the requirements: Require Phishing-resistant MFA only on hybrid joined devices (Entra joined could also be included if appropriate).