I thought that a single point of failure was a bad thing. Sure you might want to only have a single place where things can fail, but if that failure is catastrophic...
- Having webmail which is not protected with two factor authentication
- Enabling POP/IMAP which also does not have two factor authentication
Think about failure like resistance. Points of failure in parallel gives less overall risk of failure. Points of failure in serial (like adding a front-end) gives greater overall risk of failure.