Physical authenticator battery finally depletes and unsyncs

So my trusty physical authenticator finally kicked the bucket after probably a year of BATTERY 000 messages, quite impressive really. I have some questions regarding getting rid of it and adding the mobile authenticator.

I have one PC where my bnet automagically logs in, a trusted unit or whatever. My questions are as follows:

  1. Can I change the password without removing the authenticator first? The reasoning for this is I’ve read about monitoring armories for the authenticator pet and hacking attempts when it is removed. It wouldn’t take long to do but it feels sweaty.
    And yes, it is an old password.

  2. Can I remove the authenticator without using a code from it? It would be awkward if removing it requires a code from it, thus putting my trusted unit into a state of limbo.

  3. This is tangential, but disabling the setting “Always require authenticator for login” in the Account Settings - Security tab, does that imply that the “usual” log in spots are flagged as ok and any unusual spot requires the authenticator? I see that some of my logins are from a geographical location quite some distance away, though in the same country. I’d chalk this up to IP shenanigans or maybe a refreshed IP at some point.