This message comes from 2fa. It looks you the only configured mfa method is twofactor Nextcloud notification which the system enforce here. as an admin you can lift multi-factor requirement and remove registered devices (or create one-time 2FA code using twofactor admin app).
When you login into users account always double check you are allowed to access the data - especially in case some private data could exist in the account - always involve have multiple people like HR and data protection officer and document the process to avoid legal issues.
Best practice would be to implement some process where leaving employees could take out/delete their data and hand over remaining company assets to somebody else.