Correct...BUT, here is the problem. While its 100% true you can do so and lots of customer do, issue is that to tie different auth method to different group, according to TAC is not possible, unlike you can do on Fortigate firewall, does not work same on CP.
They advised me about a year ago that this was something R&D was looking into, they even sent me an official email they got from esc team (see below)
Andy
CP actual response (January 2023)
Hello Andy,
After consulting with escalations, assigning specific users to desired authentication method in Check Point Multiple Login Options is not a supported feature yet, and there is already an existing RFE submitted for that. However, you can configure only RADIUS authentication, and have the RADIUS server determine who gets MFA or who does not, meaning configure the MFA on the RADIUS server/Using DUO or some other MFA services on the account itself instead of having the gateway to do the MFA