Yep, we use the two factor authentication that's built into Microsoft 365. You should have MFA enabled for all your users already, but you can also add it as specific requirement for the VPN connections via a conditional access policy that targets the VPN application that you will create in Entra.
... View more