JM Admin Role Lock stops new Administrator accounts. Users who are already Administrators stay Administrators. Nobody else can be given that role.
The plugin blocks the role when WordPress saves it:
On activation the plugin writes the current Administrator user IDs to administrators.json in a jm-admin-role-lock folder inside the uploads directory. On every request it compares that file with the database. A user who has the Administrator role in the database but is not listed in the file loses the role before the request continues. When an allowed Administrator is demoted, their ID is removed from the file.
There is no settings screen.
Multisite Super Admin is a network privilege, separate from the Administrator role on a site. This plugin does not change Super Admin.
A SQL query can write the role into the database. The next WordPress request removes it again, as long as administrators.json is still the list created by the plugin.
Deleting that file makes the plugin take a new snapshot from whoever is an Administrator in the database at that moment. Anyone who can edit files on the server can edit the JSON and add an ID.