> But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app?
By ensuring that whoever signs into the account has at least two distinct factors: the password and the trusted phone with the authenticator app. One thing you know, one thing you have. Perfect. (Depending on your phone's settings around biometric unlock, it might be even the trifecta: one thing you know, one thing you have, and one thing you are).
Let's imagine we implemented your suggestion of requiring the login to be on a different device than the authenticator app. What threat model does this protect against? An attacker who has your password and the unlocked phone will just sign in from a different device with the password, and then use the authenticator app from the phone. The only people you're protected against are those who do not have any access to another device than the stolen phone.