Why transfer to another CMS requires 2FA ? I do not see any good reason, there are much more dangerous operations that can be performed without 2FA
Issue
If 2FA is not enabled on the cms there isn’t any good reason to require it for a single functionality.