I managed to reset my password, and figured I'd enable 2FA while I'm at it, but it was already set up. At no point was my reset challenged.
This seems like a flaw?