If an attacker has one of your devices, bypassing SMS is even easier. Nor does passwordless login have to rely on biometrics. If you consider it insecure, use a pin or a rolling authenticator code.
Honestly, some people are so anxious to knock Microsoft, you deny basica reality. These schemes are more secure than sending a password over the open Internet, then responding to a plaintext SMS message.
We're speaking of FIDO2 passkeys here, which are not passwords. You may be thinking of a pin, which one could indeed call a password, but is a little harder to spoof, since it never leaves your device.
But they can't. Whether you're speaking of a FIDO passkey or a pin, they are tied to a specific device. I could tell you my pin now is "1234", and that does you absolutely no good without access to the device that pin is associated with.
I think you've misread my statement. I was responding to the claim that any two factors are inherently better than any (different) single factor. Mathematically, this is false. If you use 2FA with each factor being 90% secure, that's more vulnerable than a single factor 99.9% secure.