Another policy using this concept with Filter for devices to only target devices/users that should be able to meet the requirements: Require Phishing-resistant MFA only on hybrid joined devices (Entra joined could also be included if appropriate).
In-place upgrade directly to Windows Server 2025 supported the whole way back to 2012 R2! Impressive.
https://learn.microsoft.com/en-us/windows-server/get-started/upgrade-overview