currently 2FA is set within the individual account, meaning a co worker is entrusted to turn on 2FA as per company policy
we would like a feature where 2FA is set at an app level and is enforced on all members, meaning they cannot themselves individually turn this on and off as they desire
once enabled, it would log users out and enforce 2fa on next login
