Here is a link detailing different MFA efforts for ISE
For Device Administration, we do 2 factor through the use of CAC/PIV cards and the Pragma SSH Client
I found my issue, i was not using DUO correctly. I set it up as a Radius Token server and then used it as an identity store in my authentication profile. I was not quite please with the process of the MFA with DUO so i tried to use Microsoft Azure MFA the same way. the results were exactly what I was looking for. On Cisco devices that I tried to SSH into I would either get a prompt for my token or a push notification. This was based on how I wanted my MFA to do. Even tried it with a phone call, the timeout for radius will need to be longer for that. No extra configuration for my network devices or anyconnect VPN.