A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Though the specific details aren't clear to me, it appears that the use of a rooted device or otherwise modified Android operating system might be detected by the Microsoft Authenticator and/or cause problems with Entra accounts, since the integrity of the phone operating system itself would be something that Microsofrt would consider a security risk.
Here's the DuckDuckGo search I did to find the articles discussing this which might provide some aid in understanding the issues more deeply.
GrapheneOS compatibility with Microsoft Authenticator
Unfortunately, the issue of personal privacy and security you're running into are really different sides of the same coin and as such have both overlapping as well as separate concerns, which when using private devices within work environments are even more likely to collide with business best practices, vs personal privacy preferences.
As a past security professional working in corporate and education environments, with my own preferences for highly private use of my devices, I ran into these collisions many times during my career and even since, so finding a happy balance is even more difficult for us than the typical consumer who's often oblivious to these concerns.
IOW, I see what you're trying to do but am betting it's an overly complex combination at best and nearly impossible to resolve question at worst. For those reasons I personally wouldn't even try this combination, but that's my take having typically been more concerned with the security of both the organization(s) I was working for and more importantly the employees I was trying to protect.
Rob