I'm not super knowledgeable about the Secure Connect because I haven't deployed it yet, but I'm fairly sure 2FA challenges would be handled by your IDP provider because that's how it works with AnyConnect, unless you opt to utilize Meraki Cloud Authentication. It entirely depends on the IDP provider to issue MFA challenges. For example, here's how to configure MFA challenges for Microsoft Entra ID in the MS admin portal. Ref: Meraki Cloud Authentication (Cisco Secure Connect Embedded) - Cisco Meraki Documentation
... View more