2FA segmented by user (R80.10)

When implementing 2FA with SMS gateway and AD (in R80.10), is it possible to have some users with 2FA and others not? The purpose it to have superadmins which can remotely access when there are issues with the SMS gateway.

Or the segmentation must be between AD users and local users?

Also for the purpose of testing, how can we setup only a user with 2FA (without enabling 2FA for all users)?