EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through.
Impersonate the person out of town to escalate to their privilege level.
Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely to work as the org scales up in size (think enterprises with their own helpdesk).
Once you have email and/or other federated access, you have a toehold. Bonus points if you've cloned their work cell SIM or have rerouted SIP for their desk phone to keep them out of the loop. I have seen weaker phishing attacks on financial/accounting staff who have the authority to move millions of dollars of corporate funds.
EDIT:
> Whom the would-be attackers send this email to?
Phishing target
> Do they send this email from their own email address?
Throw away address or spoofed address from a familiar-to-the-business domain.
> Is there an assumption that sysadmin/support team will blindly reset a password on someone else's request?
This is one assumption.
> How do attackers bypass corporate VPN?
VPN access might not be required to obtain the level of access desired. Do all of your SaaS providers require 2FA? Your business bank accounts?