MFA would be mostly useless, if you could add a trusted device without verification (only have username/password).
You should encourage your users to have an alternate MFA method besides the authenticator app.
If the user can not access their MFA device, the account can only be reset by the Account Administrator.