I am able to use the answer in this question to enforce MFA on individual IAM users and groups, via a policy: Can you require MFA for AWS IAM accounts?
But if someone creates a new IAM user, that user is not subject to the same restrictions. Is there some way to enforce MFA for all IAM users, including ones which haven't been created yet?