You might try setting up a Conditional Access requiring MFA and then selecting Office 365 application (cloud apps, not the software).
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Microsoft no longer supports MFA server for new deployments, but recommends using the [NPS Extension for MFA configuration](https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg "MFA NPS Extension").
[Hybrid Modern Authentication](https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-hybrid-modern-authentication-for-exchange-on-premises/ba-p/607476 "Hybrid Modern Authentication") works for Outlook clients, but does not appear to provide MFA enforcement for OWA. In our scenario, we have Azure AD Connect deployed with pass-through authentication (No ADFS). Is there a way to enforce MFA on OWA for end users either using the NPS extension or another AD cloud service? We have Exchange 2016 Server with CU 15 deployed.
You might try setting up a Conditional Access requiring MFA and then selecting Office 365 application (cloud apps, not the software).