Personally I hate when I use a passkey but then still get hit with an SMS second factor step. A passkey should be enough, unless I'm changing my recovery email or withdrawing a million dollars or something. Also there's still a lot of really bad UX around passkeys, both by browser/OS vendors and by individual apps, and unimplemented features like sharing.

Passkeys are the right thing but they need more work.

I totally believe that someone has gotten it this wrong, but personally I've never seen an SMS 2FA on a Passkey authentication. My most common Passkey complaint is that a service doesn't support them yet.

The worst part is: why are they sending me an SMS when I never configured that as an MFA option?