2FA with Office 365 - idiot's guide?

Yeah you learn really quick the stock android / iOS mail apps really suck.

Use Outlook, OR if you have a power user on Android, suggest to them Nine Folders.

I will NOT use anything but Nine for myself anymore, best $10 I ever spent.

I don't think you have to leave the app open the whole time.

Also, I believe Outlook can now utilize the Primary Refresh Token. So, if the device is at least AD registered, they may never have to do MFA until a password reset, as long as they use the computer within a span of 14 days.