Yes, works well...the only gotcha I have found to be aware of...if said person uses the temporary code in the gmail app on a phone, you may have to repeat as the gmail app doesn't appear to kick off the required process to complete the process and continue to setup 2fa...but if you coach the user to use a browser it does work as expected...after you generate the temporary codes the person is appropriately prompted the next time they attempt a login.
I have found this also works when I create a user in an enforced 2fa OU...and the user doesn't attempt the login in the required time (as the counter seems to start when you create the user, not first login). I ran into new staff members over the summer...I would create them and then too much time passed prior to their first attempt.