In our company we have setup Bitbucket (premium level) to use two-step verification (workspace settings -> access controls -> select two-step-ver). Which typically involves just setting up an authorization app on mobile like Authy or Google Authenticator, or MS Authenticator. Along with the team members valid email account number.
To see the projects, and repositories on the dashboard team members are told they have to add a public SSH key to complete the access. Is this additional (3rd step) required and why. While I understand the additional uses and functions that SSH affords. Why is it a necessity here?
Some companies don't allow clients like OpenSSH to be enabled on the desktops. Also not every team or user should be assumed to know how to setup and manage SSH keys (while most probably do - it is still a big assumption).
If SSH is not required with 2FA enabled then please explain what needs to be "unset" to remove the requirement.