So I digged into it, and changed my opinion - Microsoft is right, for the Microsoft Account, using a password locally instead of a PIN is LESS secure.
TL;DR: if you want to allow offline login, you need to keep the hash/token to the Microsoft Account locally, and this is dangerous, some malware could steal that, and impersonate you to login to your Microsoft Account. Using a TPM PIN removes this threat - the hash/token is never kept locally, so there is nothing to steal, and Microsoft could still ask for the account password from time to time when they need to refresh the token, and you can't brute force the short PIN (yes, this requires trusting the TPM)
> I just don't want my online services account being the thing that controls access to my local computers. Especially when it can be locked or deleted by Microsoft for whatever reason.
That never happens. You can boot from an Windows install ISO and reset the credentials if you really need to get in. True, might be difficult for your average user.