Last month Password-less AAD SMS Authentication was released to Public Preview.
Is this considered MFA? MFA is typically considered at least two of "Something you have/are/know", but in this case it seems to only be "Something you have"?
Also, how safe is password-less SMS authentication? SMS might not be very easy to spoof from a great distance, but they aren't encrypted either.
In contrast with the Authenticator app which is both encrypted and the password-less authentication require the app (something you have) and a Pin (something you know) or a Biometric (something you are).
At the moment this is limited not to work with Native Office apps, but hopefully that will be remedied, in which case it will be a great complement in the battle for those resisting MFA.