I love this answer https://developers.login.gov/faq/
Can we turn off two factor authentication?
- No.
And that's how it should be answered.
As IDP in a SSO context that's the only acceptable answer: NO, the SP can't and shall not be able to disable user's 2FA.