Hi @danielesquaranti,
Currently, it is not supported to use SAML and certificate at the same time. Client certificate is requested by ASA, not ISE, in the authentication process on VPN.
You could enforce additional conditions in the Conditional Access Policy on Azure side, and to ask for 'Managed Device' condition to be satisfied too. This is also checking of certificate on your machine, just different one (they will be Azure issued certificates, issued upon Azure enroll process).
BR,
Milos