Problems would happen when the new person tried to log in to the account. Since the login was from an unrecognized device and an unrecognized IP address, security was tightened. Even after inputting the correct password and entering the right backup email, it was mandatory to enter an SMS message from the phone number tied to the account, even after various troubleshooting and attempted workarounds. That meant getting ahold of the previous executive, who may be busy or changed their number.
You could argue that Gmails weren't meant to be used this way, which is fair; the goal of this comment is just to provide additional evidence that the description provided by the parent comment is true. (In the end, we went for a low-cost, reliable email service to fix the issue in the long-term. We also found that registered non-profits are eligible for free Google Workspace or Microsoft Outlook email plans subject to certain eligibility conditions, though we did not have a need of becoming an officially registered non-profit at the time.)
The difficulties were to be expected as personal Gmails weren't meant to be used like this (the goal was just to share an anecdote about the difficulties of phone numbers used for two-factor authentication with the free service even once a year). The long-term solution we used was to pay for a reliable but low-cost (in comparison to Outlook and Google) email host initially recommended on HN and a few sysadmin forums, to gain access to organization-wide admin features.
[1] https://support.google.com/a/answer/2537800?hl=en#zippy=%2Cc...
1) Not providing phone number for 2FA. Never.
2) Using multiple (3 pcs.) physical keys for 2FA (like Yubikey and similar). Authentication app is an alternative for one choice of 2FA (but not the sole one!)
3) Only using a limited set of Google functionality. Use for secondary purposes mostly.
Well, the last one is mainly to mitigate the consequences if happens anyway, for other reasons too (like with that poor guy who made picture of his own naked baby for a remote diagnostics with his doctor and the Google locked him out for months - and still counting at the time of the article - for child pornography) 1) Don't use anything Google.Really?
Or did you just toss that in for the free upvotes?
Alternatively you can purchase a hardware key and store it in a trusted place, but admittedly they are expensive, so OTBC is the usual route.
I'm logged in to such an account right now and there's no way to do this. The account primary email is also set as the recovery email address and there's no way to add another.
It's actually deceptive to the user to even call it a recovery email address in this case, since Google will never offer to alternatively send a verification code there if the 2FA device is unavailable.
Heck, here’s an idea for a startup: a digital “moving” service. IRL I could pay a company to take everything I own, pack it up, ship it somewhere else, and even unpack it too. I’d like to see a digital equivalent.