It's two passwords, both are something you have to know, there's nothing you need to have or be (sms and biometrics respectively)
But if you can access the phone content remotely behind a password, then it stops being 2FA.
It's two passwords, both are something you have to know, there's nothing you need to have or be (sms and biometrics respectively)