I can guess.
People lose or break their phones often enough. It is a routine thing in an organisation of just 120 people. Now imagine that instead of an educated and selective group, you are dealing with a pool of desperately partying, drunk globetrotting influencers, political figures with Neanderthal technical skills or other walking security disasters.
How often do you think account recovery due to lost 2FA would be triggered?
For proper protection you need hardware 2FA, and for usability reasons you really need the NFC enabled Yubikey so the same second factor can be neatly enforced on a mobile phone too. But you can't have just one. If the access is for anything non-trivial or of high importance, you need at least two such devices. Preferably three.
That's a lot of Yubikeys you need to subsidise, because most people sure as hell are not buying them out of their own pocket.