I found it.
in /etc/pam.d/gdm-password replace
auth required pam_succeed_if.so user != root quier_success with
auth sufficient pam_succeed_if.so user != root
Or you can create a group and use passwordless authentication based on group by replacing the above with
auth sufficient pam_succeed_if.so user ingroup GROUPNAME
Add the users to that group and restart gdm 'systemctl restart gdm'
Of course, to enable google authenticator in the first place you have to install it:
Debian:
apt install libpam-google-authenticator
Fedora:
dnf install google-authenticator
Each user has to run 'google-authenticator' and follow the prompts.