I wasn't able to find a direct answer, here are some relevant sources:
MFA self management does not respect login policy(1) : This GitHub issue describes how MFA types can be enabled/disabled in the login policy, but the setting is not respected in the self-management API and UI, allowing users to set up disabled 2FA factors even when not allowed by the login policy.