These days a lot of folks can probably do more than just authenticator on their personal device. Teams and Outlook, for example, are both able to run with the MDM-level controls the company wants but without the device-level MDM. It's part of the app and has no control over anything else.