Allow SMS MFA for only certain applications

Can I define which applications on a tenant are eligible for SMS MFA, blocking this option for others, or is it cleaner to have separate tenants for apps that can/cannot use SMS MFA? TIA