I have to add that feature is also missing on FPR appliances running FTD software:
Cisco FPR-1000 Series
Cisco FPR-1100 Series
Cisco FPR-2100 Series
Cisco FPR-4100 Series
Cisco FPR-9300 Series
MFA feature can be implement with RADIUS protocol since FTD 6.4 (newer) as secondary authorization method.
Be aware that you have to deploy a MS-NPS / RSA / Duo Access (docker container) server in order to use RADIUS relay proxy for MFA.
The RADIUS NPS service is not available for all cloud services like MS Azure cloud.