It seems to me that if you choose the no-password route with a 2 Factor Authentication, it becomes way more intrusive for the user than having a password and 2 Factor Authentication, because you're constantly being made aware that there are login attempts.
I appreciate that given the latter method there is a slight element of "ignorance is bliss", but I'd rathe have that than constantly being asked to authenticate (which in itself carries a further risk).
However irritating it might be it's worth choosing an alias (or trying an alias) that is fairly complex - as long as you can remember it.
I don't know how on earth they (the hackers) would get hold of the new alias as long as it's not posted or used to log into anywhere, unless MS servers are being hacked or your computer isn't clean.
(Important: You must disable the "hack-attempted" email address from being used to log in.)