A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
It's not impossible, you just have to have at least 2 alternate methods of verification available even if some of these are lost, which in most cases means at least 3 and better off 4 or more optional methods when available.
As a past network administrator and security professional, this is obvious to me, but unfortunately something that many consumers simply don't seem to get, regardless of the fact that Microsoft typically prompts them to add more verification methods whenever they get the chance.
I personally have the Microsoft account password which I won't remove until Microsoft realizes the precise issue you're bringing up here, the legacy SMS phone option that's currently in process of being dropped, a secondary Gmail used only for verification and not stupidly synced as the Microsoft account name that's just asking for trouble like account theft or loss since then it's not useable as an alternate method (the Microsoft account is legacy MSN domain), Microsoft Authenticator backed up to the Google cloud for recovery, Windows Hello Face (camera) and PIN on a Microsoft Surface Go tablet which also uses a Passkey for background login to the account (both that device and another without a camera are registered as trusted devices in the account), and lastly a Microsoft account Recovery key which may not be useable since it's not actually listed among the verification methods, but really should be since it acts as a form of identity that supposedly only the account owner should know.
The chances I wouldn't have at least 2 of the above verification methods available is unlikely, at least once I'm home if the house hasn't been destroyed with all of my devices including the phone contained inside it. But that's why the Recovery Key should still be useable as a verification backup if it isn't. since not everyone has the smartphone or other hardware available for things like Windows Hello, and it's something you could print out and store offsite in a safe deposit box for example.
Unfortunately, many people are learning these technical issues with account security and verification methods the hard way, which hopefully they'll use as a learning experience to be better prepared in case something catastrophic happens to them in the future.
Another option you might consider for the future is a combination of a Passkey with Passwordless account option, since though that removes the password as a verification method entirely, it only leaves less easily phished or otherwise stolen methods, while moving ahead with the generally safer Passkey method that Microsoft and other vendors are supporting since it's phishing resistant. It also would remove the risk that you lose the account due to 2FA.
Rob