Is it meant to be like if you enable 2FA auth for users that the if that user creates a QR code for a mobile that the 2FA check is omitted when using that QR code?
From a security standpoint i could understand this if the QR code has a limited validity lifetime, but aparently its valid forever...