i just realized something else is broken - not sure others are experiencing the same, but here goes:
before this update, it was possible to use the MS Authenticator app installed in android fully managed device as MFA - the azure account that would appear in the app right after the phone enrollment would merge with the account added via standard MFA enrollment flow (scan QR code,etc). however, now if creates A NEW ONE, plus it only allows to satisfy MFA with a code (i.e. no prompts available), and it's more complicated to finish the process for new accounts.
also, if I try to enroll via phone by opening a mobile browser and go to my account page, the "Pair your account to the app by clicking this link" is not available anymore, instead, it directs me to open authenticator app, add "other" account, and then copy/paste the user id (email) and a security code...
honestly, it's just all broken now. it used to work flawlessly, now it doesn't. this is frustrating..
can anyone please tell me what is the scenario that results in successfully enroller android fully managed phone and MFA set up?