Admin Users can enable 2FA per user, using the tickbox on the Edit User form
To enforce 2FA for ALL users, update the General Setting 'require_2fa' from 'false' to 'true'.
Logout and then Login, if it's not setup, you will be prompted to Scan a QR code with your phone into an Authenticator App (like Google Authenticator) and Confirm a One Time Password (OTP) code.
You will then be prompted for a OTP when logging in.
Users can reset the 2FA Code from their Account Menu.