The phone had been replaced so Google Authenticator app had to be reinstalled. This requires to scan a barcode and while there's no access to admin, there's no access to barcode too. The admin can't access the site because of this.
If Defender is disabled, admin can access the site but enabling it back enables 2FA again too and kicks the admin out of the site.
The "lost your phone" option is enabled but the e-mail doesn't get to the inbox, unfortunately. Is there any way to fully disable or reset 2FA for a given account using some additional code snippet or directly via DB so it could be set up again from scratch?