Full AWS Practitioner Certification Question

When implementing delegated administration for a Microsoft partner to manage a customer's Microsoft 365 tenant, which configuration ensures the partner can assign administrative roles to users within the customer's organization while adhering to a strict security compliance requirement of limiting the partner's access to multi-factor authentication (MFA) management for the customer's tenant?