You're just adding more points of failure.
Think about failure like resistance. Points of failure in parallel gives less overall risk of failure. Points of failure in serial (like adding a front-end) gives greater overall risk of failure.
- Having webmail which is not protected with two factor authentication
- Enabling POP/IMAP which also does not have two factor authentication