CyrilMjt sounds like an easy change but probably isn't. there is difference between a "normal" website like this, which can hook into the broader F5 authentication setup then an appliance which also supports totally not web related authentication methods. Next to that the proces of getting something fundamental like this added is gonna take time.
There are several ways to add MFA to the F5 BIG-IP appliance, you could handle it on the RADIUS or TACACS server if those allow it. Another way is to use the APM module for the admin authentication.