And as they say in the letter, MS Authenticator (which is not even really a 2FA system but a passwordless authentication product, likely the best on the market right now) is not even mandatory as SMS is also an option. Setting downsides of SMS 2FA aside, they are not actually being required to use proprietary software, but instead seem to have bundled two mostly unrelated concerns together. I mean, they're objecting to having to share their phone number with MS... In order to access their email that MS hosts. The privacy boundary they're making this stand over is just a very strange one.
TOTP isn't really a drop in replacement either, as MS Authenticator is intended to protect against a couple of classes of attacks that TOTP doesn't, most importantly 2FA interactive phishing, which TOTP remains vulnerable to. Following the Okta attacks a number of organizations have prohibited TOTP, as interactive phishing of TOTP tokens is becoming pretty common such that TOTP 2FA is no longer substantial protection against this extremely common attack vector. FIDO is another good option but frankly the usability of FIDO remains very poor and it produces a much higher volume of support issues than app-based interactive verification.