Granular access to selectes SP Site

Hi, I need to configure secure repository for certain files that must be accessed to a restricted group of people. These files aren't office files, so they cannot be modified from web, but they should be opened from Desktop apps (i.e. Autocad files, Alias, ecc.). They must be also access this repository with MFA and accepted term of use, only from two deviceid. (very strictly)

I though to use Authentication Context and sensitivity labels, but with this function i cannot sync the repository with ondrive. I would like to use Conditional access, but i cannot assign only for a single SP site.


any suggestions? 



