To the first question, there is no way to achieve that at the moment; all callers will require PIN when hitting the AA if PIN is enabled. It would require a new feature on the OBi.
For the updated question, it should be achievable with something like this:
{(11111111|22222222):aa},{?|@:}
NOTE: the () in the 1st rule is not necessary (but ok) for hard-coded numbers; until
you want to replace the hard-coded numbers with digitmap rules, like (1xxxxxxx|2xxxxxx.)