Jamf Pro would satisfy that. But you really should to try multiple products to make an informed decision. Some products integrate with some MDM products. Example being Okta and Jamf Connect. Just remember regardless of your choice you will have to unenroll your current devices and re-enroll to the new system. If you don't have time or headcount for that, hire a consultant and go from there. Also pro-tip don't make MFA an option to disable, rather find a way to make it work to your advantage (again consultant might be the best route). You can get really screwed without it. Plus NIST and compliance usually requires it regardless of what your bosses prefer.