This concerned me at first but as previously suggested, the two "Microsoft-managed" MFA policies under Conditional Access can simply be toggled off to prevent them being automatically enabled. We're already implementing our own policies so only these will be used going forward unless we decide to toggle the Microsoft policies back on.