I set up firewall rules on our wp-login pages that were getting hammered, to challenge with a capatcha. I am finding that employees who frequently use WP for edits are being asked over and over to challenge. Can I set up exclusions based on users email to go around these challenges?

Cloudflare has no way of knowing the email address of your users with Firewall rules, so no. You could add their IP address to be allowed, though.

If you are looking for something authentication based, I would recommend using Cloudflare Access to protect the page Access | Zero Trust Network Access


