It uses the Duo native SAML interface for the MFA. You can use push, verified push, TXT, phone call, FIDO2, Windows Hello, etc. Anything you want to allow in your policy.
It allows Duo trust policies to be used. Depending on your plan, you have have it check if antivirus is running, is the machine authorised, is it a member of AD or Intune, etc.
You can enable features Duo like inline password-reset for people's who password has expired. This whole class of calls tot he help desk can be eliminated.
You can use actuall SSO - so once logged in via Duo, the user is automatically logged into every other app using Duo.