I agree on the 'customer support backdoor,' with some caveats. I worked for a small IT Services provider, and we a policy of "don't do dangerous stuff that an unknown party asks for unless a known party verifies it." But sometimes someone gets fired, and there are no known parties, especially with cloud services.
I realize there has to be a way to work around 2FA, for situations like loss of device, terminations, etc, but that should have some known policy way of verifying (say, you must send a notarized or local equivalent letter, or appear in person somehow) identity, especially for a cloud service.
(Totally incidental and you perhaps won't see this, but, r1ch, Conflict Crusher was instrumental in 15 year old me learning how to mod TA, which led me to learn how write BOS scripts, which led me to realize that I liked this programming thing, which led me to my current career/way to support my family. Thanks! :) )