Disabled by administrator
In Account → Settings, the Google Authenticator row shows Disabled by administrator when two-factor is not allowed on the site (totpAllowed false). Companion line: authenticator is unavailable on this site.
Why this happens
Admin Two-factor authentication mode is off (or otherwise not allowing member TOTP). This is a status label, not a failed API call — members cannot set up or turn on authenticator until the site allows it.
Diagnose and fix
1. Admin: Settings → Security → Two-factor authentication mode — enable optional or mandatory as intended.
2. Members: refresh Account Settings after the change; then use setup / turn on.
3. Distinct from Could not disable 2FA (mandatory mode blocks turning off) and from setup API failures.