Emergency access
Design break-glass accounts for resilience without creating an unmonitored bypass
Emergency access accounts exist for events such as federation failure, MFA service disruption, administrator lockout, Conditional Access error, or loss of normal credentials. They should not be used for daily administration. Maintain at least two accounts so one credential or method failure does not remove the final recovery path. Keep them cloud-only and independent from on-premises synchronization or federation dependencies.
Assign only the authority required for recovery and document when a broader role is justified. Protect credentials or authentication devices through separate physical and administrative custody. Exclude the accounts from normal Conditional Access policies only as required by the recovery design. Configure high-priority monitoring for any sign-in, credential change, role change, method registration, or policy change involving the accounts.
Test on a documented schedule. A test should confirm that authorized custodians can retrieve the credential, access the correct tenant, satisfy the intended method, reach recovery functions, create a traceable event, and rotate or reseal the credential after use. Record the result without placing the secret in the evidence package.
Business impact: an untested emergency account can fail during an identity outage; an overused or weakly monitored account can become a permanent path around the organization’s strongest controls.