Because, the main reason why I ask if I can keep "First Factor/Second Factor "after max failure attempts is...
I enabled SSSD offline authentication.
if SSSD be goes to offline, ssh prompt changes from "First Factor/Second Factor" to "Passowrd:".
But If I get 'Password:' prompt for the locked user, offline and lockout status can't be identified by the prompt in the user's perspective.