Add an Enterprise Policy to forbid users from enabling two-step-login

@kpiris As you also aim at SSO, I think your request essentially is the same as: Ability to Disable User-Added 2FA When SSO Is Enforced - do you agree?