Two-factor authentication was enabled on a colleague’s account without their knowledge. As a result, they are unable to log in. The account is not configured in any authentication application, and there is no mobile phone number associated with it. How can my colleague proceed in order to resolve this situation?