Hi Robert,
Thanks for your reply. The change does break our use-case – we need 2fa for all admins except our one ’emergency access’ user which has a strong password and is not used day-to-day, rather it is reserved for hosting admins to access a customers site if needed. 2fa is not suitable for this account since it needs to be shared.
Neil