Great series @haslund! 👏 I hope I'll have time to watch the complete playlist.
About this question; I've gone with answer 1. While answer 3 with the seperare forest would be a better solution, I thought that two-factor authentication with service accounts won't work. It may depend on the definition of service account, but if those are for example the guest credentials, then we can't use two-factor?