Always try password before keyboard-interactive for the first factor. After
any partial success, prefer keyboard-interactive when the server still allows
it so multi-factor/EDR second factors work without a per-host switch. Remove
the requiresMfa UI and "remember MFA" checkbox; keep secondary-prompt
protections and hostId-aware password save.