It's also impossible to delegate this authority to anyone other than the account owner, and there's no concept of shared or service accounts, so nobody other than the account owner, with access to their 2FA method is able to do this.
Heaven forbid if the account owner was ever to put their 2FA method as a personal device / phone and then leave the company.