I work in the industry if it wasn't obvious though for years now nothing to do with phishing but I do have some experience shall we say.
1. Building a phishing page and can accept 2FA and in real time(remember code is useless after 30 sec) logs in to an account is much harder. most attacks are low quality junk.
2. From a detection standpoint, this is awesome. the attacker has to log in real-time. he will likely send that link to hundreds of people = good telemetry to detect anomalies\fraudulent logins.
3.* Another pain I remember observing was regarding the login process itself. Websites tend to change their log in UI\processes, different websites have different layouts.
This makes it frustrating and tedious maintain, bank changes the login prompt, attacker has to modify code to accommodate that.
4. Data doesn't lie, it is not bulletproof but it does offer significantly higher level of protection. saw that in actual enterprise with my own eyes.