I haven't received that letter but it appears legitimate. You can try mousing over the link and see if it directs to an Apple.com address.
It is easy to not pay attention when signing into Apple if you do not yet have 2FA. They present you with several screens and you have to really pay attention to which buttons you click if you do not want to sign up for 2FA.
Note that you have 2 weeks to turn it off if you want to, then it is permanent. I would say if you can tolerate it then stick with it since it is the way security is being done now by everybody.
Identify legitimate emails from the App Store or iTunes Store - Apple Support
Recognize and avoid phishing messages, phony support calls, and other scams - Apple Support