When new accounts are created, currently, Admins need to enable 2FA on the account manually. This can lead to ad-hoc accounts not being protected. In today's climate, it is much more likely that an organisation requires 2FA and will disable it for a small minority (and probably temporarily) than it is to have it not configured en masse and enabling it sporadically.
I think all accounts should be enabled for 2FA as soon as they are created, thus taking a step out of the admin task of creating accounts.