TSO VERIFYAPPL(ON) was set in IBM's MFA, but the APPL is not being passed. How does that work with ACF2?
The ACF2 TSO interface will use the APPL in the GSO TSO TSOGNAME field if it's filled in. This will work for the MFABYPASS rules.
But, there is a catch. TSOGNAME is also used as the APPL when a user logs onto TSO with a passticket. So if you use passtickets at TSO signon, make sure those still work. You could always set the TSOGNAME to TSO followed by the LPAR sysid - this is what passtickets will use when TSOGNAME is not filled in.
Example: if your LPAR sysid is TPCQ then set TSOGNAME(TSOTPCQ) and make a rule for MFABYPASS.APPL.TSOTPCQ. This way, it should work for both MFA and for passtickets.