Introduces admin endpoints to require or make MFA optional for users, and adds pessimistic locking to user settings updates for MFA operations. Improves consistency in MFA state changes, updates related service and repository methods, and enhances test coverage for MFA setup logic.