Hi heeizi
While Microsoft documentation only supports Trusted Signal as the second unlock factor, your test demonstrates that other credential provider combinations may still work in current builds. However, behavior outside the documented Trusted Signal Unlock configuration is considered unsupported and may change without notice in future Windows releases. The fact that PIN + Facial Recognition currently functions does not imply Microsoft support or a supported security boundary. Administrators should rely on documented configurations when designing production deployments.