Can you enforce 2FA on basic or standard non-plus accounts?

I’m wondering if there is a way to enforce 2FA on non-plus accounts. I can see that individual users can opt-in to 2FA but I need them to be forced to use 2FA. I would think such a standard security practice would be available to all plans. Passwords-only on a web accessible system for guarding brand and business financials would be a very bad look.

ps. “Technical Q&A” requires a label, I am not allow to create one (would have labeled “security”) and the only available options are irrelevant