When you use Azure AD to login to the POS, the authentication is done against an Azure AD App (d5527362-3bc8-4e63-b5b3-606dc14747e9) which lies in Microsoft owned tenant. If you are somehow able to bring this cloud Apps field in the Conditional policy, you might be able achieve something close.
Adding a screenshot from the login audit:
Commerce Store App / Modern POS:

Cloud POS:

If this helped you, I'd appreciate it if you'd mark this as a Verified Answer, which may in turn help others as well.