I created a user pool in AWS Cognito with MFA set to optional

and adaptative authentication as Optional MFA.
The MFA method enabled for users is TOTP, which I enable by calling SetUserMFAPreference.
My use case requires that any user that uninstalls their TOTP app or buys a new mobile phone can install it again in their new device by generating a new valid TOTP token. The only way to generate a new TOTP valid token is by calling AssociateSoftwareToken, but it requires an access token that the user does not have as they are not signed in yet.
I tried with SetUserMFAPreference setting enabled=false but it did not work. Sign in still requires the TOTP challenge.
Is there any way to disable MFA or regenerate a new TOTP token to achieve below behaviour?
