You have me thinking. What about if you configure SAML (you can use Entra ID)? You would use your SAML credentials and SAML MFA, and then the SAML access token would be stored for as long as your SAML provider permits, and you can use biometric authentication on your phone. A heavy solution for the problem, but it is an option for you. And if you are heavily regulated, this is likely to tick additional boxes.
... View more