You’ve run into a pretty common roadblock when trying to use AirTags (or really, most Find My–dependent accessories) on devices managed through MDM. AirTags are tightly tied to Apple Accounts and the Find My network, which Apple restricts heavily for enterprise/education accounts.
The fact that you’re using a .appleaccount.com Apple Account is the key issue here. Those types of accounts are what Apple assigns for Managed Apple Accounts in Apple Business Manager or Apple School Manager, and by design, they don’t support features like Find My, iCloud Keychain, or AirTag pairing.
That’s why even though you’ve enabled two-factor authentication, the pairing still fails—it’s not an authentication problem, it’s a limitation of the account type. Apple does this intentionally so organizations can deploy devices without personal location tracking mixed in. If your goal is to use AirTags with those iPads, the only workaround is to sign in with a personal iCloud account that supports Find My, or pair the AirTags with a different device that’s not locked into a Managed Apple Account.