Realised a "question" type thread doesn't allow me to reply.... doh!
Thanks Tejaskumar for responding.
It is MS Auth that is being used.
And in reading further about your question regarding moving factor, I just realised that it only applies if you are after a HOTP.
We should be using TOTP
The challenge is whether using Microsoft Authenticator will default to push notification vs manual keying in of TOTP - unless it is specifically disabled in AAD MFA settings.
Perhaps the only way to get this to work without disabling AAD MFA push notification is to Google Auth?