Hi Luke, yes, it's a challenge, and you are correct that at the current time Outlook Anywhere does not support two-factor authentication.
There are a few options to consider though:
Direct Access - Direct Access extends the internal network out to your client machines, allowing only managed machines to connect. It's a seamless experience.
SSL VPN's - there are some solutions that can make VPN access pretty invisible to the user.
Something else that I have planned for a future paper - I do have a solution that might help allay those security fears, it's not two factor, but does provide significently increased security around controlling which machines are able to access Exchange remotely. I'm working on it.