Hi,
Our company is targetting to enable Azure MFA on AnyConnect VPN (we are using FTD). But we also do not want to lose the ability of our VPN to check the certificates of the device logging into the VPN. Is this possible to do? I do not see any option on how I can do this on FTD. But it would be great if someone has done this before or can point me out to the proper resources on how we can achieve this?
This is how we currently authenticate our machines/users to the VPN

We want to enable SAML but it does not give us the option to check Client Certificates.

Thank you in advance