You can choose to allow all end-users to bypass the extra-verification step in the sign-on sequence after an initial sign-on from a verified device. The device will be remembered as verified. You can turn this setting off. You can also selectively clear the trusted device list for a specific user.
Allow users to choose to bypass the extra verification step. SETTINGS > Security Policies > User Auth - Multi-Factor Authentication [Remember this device]
Clear trusted device list for an individual user. USERS > username > User Profile - User Settings - User Authentication - Multi-Factor Authentication - Change - Remembered Devices [Forget All]