I’d say so. You can’t reset an account’s password without the second factor. There’d be very little point to it otherwise.
1) Permanently lock them out of their account. Not a good customer experience and problematic in this setup (orphaned libraries)
2) Written "back-up codes", fine in theory but I'd guess a decent proportion of them are not well managed
3) Fall-back to manual verification (e.g. phone call establishing secondary information). Expensive and error prone.