Lurking to see the answer for question #3
3. If I must replace Thunderbird, what email program do you recommend? I don’t want Outlook, but prefer a secure, open source program. One into which I can easily transport my old emails from Thunderbird.
Answer is,
you don't. Thunderbird is completely compatible with OAuth2. I know, I use Thunderbird as my primary email client, and I use it on Windows 7. It will, of course, work on everything since then as well.
When you set Thunderbird for OAuth2, that's it. No more work required, and you don't have to use two factor authentication. And you can also use Outlook, everything from 2010 forward. Now, that said, there is a process that has to accomplished to do that, but it can be done.