What type of rollout do you have in mind? Usually people should login into user portal and provision the soft-token themselves. At least that's how we envisioned it.
But I know from field, that often the Installation is done by the admin.
I f he have to ask for user password, it is not very comfortable. So he should be able to get access to the QR Code through webadmin.
Sven
Astaro user since 2001 - Astaro/Sophos Partner since 2008