@GossiTheDog Is there any explanation for how heavily 'authenticator' features in MS sign-in flows beyond them wanting a beachhead on mobile?
It seems to be a surprisingly stubborn default even on accounts with registered passkeys; and surprisingly hard to remove from the MFA enrollment process even if you are twiddling all the knobs for a tenant and looking to control the situation for your users; not dealing with the random microsoft consumer account behavior.