Steps to take
- Admin enforces 2FA
- Admin enables Two-Factor TOTP
- User logs in
- User sets up TOTP
- User is redirected to TOTP challenge
If the user is quick, their TOTP app will show them the very same code as during the setup. TOTP does, however, detect code reuse and therefore will fail.