Force 2-factor authentication (2FA) for all users to comply with GDPR

Your only as strong as your weakest point - this should have been a standard part of 2FA from the outset!