Can a single AWS Client VPN Endpoint support federated and certificate-based authentication simultaneously?

We have some services running on an internal alb, that we would like to access, e.g some dashboard with sensitive data we dont want it to be publically accessible