Followed those instructions. Then I created a new Conditial access policy and told that policy to use phishing resistant MFA as shown here. I assume that phishing resistant MFA is FIdoSecurity key in authentication methods above. When done the user goes in a loop of MFA