You would need certificate based VPN to completely stop password sprays.
I may put a feature request in to Duo though, it would be great if Trusted Endpoints for SAML validated before authentication, this would be the equivalent to cert based option.