Thanks! Just to make sure I am getting this (depressing) answer right, I think you are saying:
a) I can 2Fa w/ a device and MS account. But that will use phone-based authentication, so will lock me out unless I have my phone. Also it will require me to 2Fa my MS account all the time, not just...
My Win10Pro laptop has multiple options:
Password
PIN (on TPM)
Windows Hello camera (on TPM)
Fingerprint (reportedly unreliable)
Device-based authentication on iphone, via Microsoft program.
I would like to enable multiple-factor authentication, choosing from the options I want. Specifically...