This makes social control much less complicated
Sure, I've made my attack surface larger, but for me beats having to call, email, or be screwed when I lose access to my phone.
Culprits: RSA Authenticate and Okta Verify.
My personal accounts that have 2FA are all backed up with Authy.
If that's the case with your workplace, do they issue you a phone to use for work-related stuff.
If not, why not?
Your personal device shouldn't be required to do work-related stuff, IMHO.
I'd add that since there's work-related stuff on your phone, your employer can restrict what you do/don't do with that phone and subject your personal device to its corporate policies via Mobile Device Management (MDM)[0] systems.
Even more, if you ensure that work-related stuff isn't on your personal device, issues with either device won't impact the other one.
I realize that it's out of fashion these days to keep one's work and personal lives separate. But IME, doing so is generally a good idea.
Gotcha. I encourage you to do so. I'd further encourage you (if this isn't the case already) to have your employer pay all costs associated with that other device. As it's their requirements that put you in this situation.
This always allows me to recreate the TOTP entry.
You'd never register a token with an actually secure 2FA schema (account inaccessible if token inaccessible) with just one device.
Back up your 2FA/MFA.