Ok, Microsoft, this is insane. And i don't mean to say that in a positive way. This is the second thing that takes away any control on MFA that the paying customer had.
First MSFT thought it would be a great idea to label Windows Hello PRT's to be 'as strong as' Authenticator MFA with no way around to enforce Authenticator MFA as mandatory step even when we want to use Hardware Tokens. Filed as a DCR last year still nothing has happened.
Now, ladies and gentlemen, MSFT thought of a new way to bash their valuable customers (their only right to exist) by forcing something that we cannot opt-out from for reasons only the customer can judge. The stated timeline is in our humble opinion, quite opportunistic and idiotic.
My advise to you, MSFT, start listening to your customers and hear them out. We have multiple use cases where we cannot comply with this new idea of you. We just need the opt-out.