I recently tried to use passwordless login with my Model T. But windows does not recognize it, while the YubiKey of an acquaintance did work with the same website on my machine. Also my Model T works as intended as a FIDO2 key after I enter my username and password.
Yes, I have had trouble with Microsoft as well. Most other companies like Google, Apple, banks, etc. seem to have no problem accepting FIDO2, but Microsoft also offers MFA Multifactor authentication which is not FIDO2. That method requires capturing hardware details that make it impractical for a Trezor-T device since you would expect that the hardware should not matter, just the seed. MFA does work on a Trezor-T, but only for that specific hardware device. You can load your seed in a specific Trezor-T and it will function as an MFA (no password) authentication. However, the same seed on a different Trezor-T will be denied. Also, you can only register one Trezor-T device for MFA authentication with Microsoft. So, if your device is lost, then having the seed alone will NOT get you back into your Microsoft account.
So, if you are using MFA be sure to register multiple physical hardware keys along with your Trezor-T. MS will only register one Trezor-T device in that category. Any other Trezor-T registration will result in an error because they are capturing the hardware details, and it is considered a duplicate in their database, for some strange reason.
Final conclusion is that you should always have multiple physical hardware devices including your Trezor-T if you are using MFA with Microsoft. As long as it is used with other hardware keys you should be safe enough.
Opinion. This is obviously a problem with Microsoft and how they decided to implement MFA. I submitted a support ticket a year ago, with no response. Time will tell if they ever get their acts together. The same “no password” technique works great with Google, so clearly Microsoft is lacking in their security implementations.