Hey Jason!
If users with elevated privileges have not registered a ToTP device, they will be prompted to set up ToTP. After that, they will not be prompted to use ToTP when logging in via SAML. Only if they attempt to bypass SSO and login in locally, or with a break glass account.