HOTSPOT You have a Microsoft 365 E5 subscription that contains the users shown in the following table. 
YES, NO, NO. User1 is in the right group and just needs to enable phone sign-in. User2's group isn’t included in the policy so won’t get prompts. User3 hasn't registered the Authenticator app at all. That’s how I’d map it, but open if anyone sees it different.
Pretty sure User2 would be prompted as long as they enable phone sign-in and have the app registered, regardless of group policy. Seen similar setup on a practice set. Correct me if I'm off.
