The authenticator app can ask for location directly via gps, but if your company doesn't enforce that requirement, you can deny the app that permission.
However if your org is using Azure AD or ADFS, your location will instead be inferred based on public IP and then challenged against conditional access policies.
Outside of those two scenarios, you're probably good.