The Problem
How attackers are registering their own MFA methods: 1. If your MFA method isn't fully enforced, then the attacker may be prompted to set it up. 2. Even if MFA is enforced, and the attacker tries to get into the account, they can try to register their own MFA method.
From my understanding, it seems like the Risk-based policies address issues with problem #2. Regular CA policies with P1 can protect against problem #1.
By default, there is nothing stopping a risky sign-in from registering a new MFA method... - A Risky Sign-in is separate from a sign-in from an untrusted source. The "risk" here is a metric attributed by Microsoft.