Hi Roiit, today you can require MFA during enrollment with Setup Assistant and during CP login, or just during enrollment with Setup Assistant, but not only during Company Portal login. We appreciate your feedback and have captured this and shared it with the appropriate folks.
If you’ve configured a Conditional Access policy to require multi-factor authentication (MFA), then the user will need a second device to complete MFA as the primary device cannot be used for anything else while it is being provisioned (e.g. reviewing a phone call or text).
Re: Cloud Apps – See section “Configuration in Microsoft Endpoint Manager admin center” in our post above for more information on using different cloud apps in your conditional access policies. No current plans to make the Company Portal a cloud app for MFA upon CP login only, but keep an eye out on our In development and What’s new docs for new features coming to Intune. Thanks!