I have a couple of comments and a question
Comment: when accessing MFA settings via M365 admin > settings> org settings > MFA > configure (https://admin.microsoft.com/Adminportal/Home#/Settings/Services/:/Settings/L1/MultiFactorAuth) it kicks you out to the older per user settings at https://account.activedirectory.windowsazure.com/ , this seems incongruent with the advice in the article.
On the Enforce multifactor authentication page, there is advertising for Edge and also AAD P2, I don't think this is necessary.
Question: How are you protecting users from getting out of license compliance in recommending/setup of Conditional Access policies? i.e are you checking (or advising) that all users covered by the rules need to have the appropriate license?