If they have password and 2FA on the same device, then it's not 2FA. Tell them to get an external TOTP generator, at least.
So in many case 2FA is broken unless you decorelate access to app/password and sim card, which mean accessing your apps/systems through a second device instead of your main phone such as another simless phone, laptop, ipod touch, or tablet. Most people would never do that for conveniency reason...But in that case the same search rules/laws apply to second device anyway so it doesn't change anything to the core issue.