You could get in the habit of remoting into a machine for daily use. (remote desktop, etc...)
Then the laptop just becomes a thin client. Nothing to restore because the "actual" Machine never cross the boarder.
that could be a nice workaround, leave a laptop at home and set up some kind of vpn.
just leaves the 2FA and Mobile issue
reply