Break-Glass Accounts in Entra ID: Securing Emergency Access

By · Published

A break-glass account is an administrator account that exists only for emergencies: when a Conditional Access policy locks out every administrator, the MFA service is disrupted, or the federation service fails. In day-to-day operations it is never used.

That is exactly why many Microsoft 365 environments forget it – or it exists but no longer works when it is needed. This article summarises Microsoft's current guidance and what matters in practice.

How many accounts, and what kind

Microsoft recommends at least two emergency access accounts so that losing one does not cost you all emergency access. Both are cloud-only accounts on the “onmicrosoft.com” domain – not federated and not synchronised from on-premises Active Directory. This keeps them usable even if on-premises infrastructure or the identity provider fails.

The accounts hold the Global Administrator role as a permanent active assignment rather than only “eligible” in Privileged Identity Management. In an emergency, no activation should depend on a process that may itself be disrupted.

Authentication: phishing-resistant and different from daily use

Microsoft enforces mandatory multifactor authentication for its admin portals. Emergency accounts therefore need a strong method that satisfies this requirement. A passkey (FIDO2 security key) is recommended; organisations running their own PKI can use certificate-based authentication instead.

The key point is the difference from normal admin accounts: emergency accounts should use a different method. If the cellular network fails and the Authenticator app does not work, the hardware key still does.

Excluding them from Conditional Access

Emergency accounts are excluded from every Conditional Access policy that can block or restrict sign-in. The cleanest way is a dedicated security group that is listed as an exclusion in each relevant policy. Policies in report-only mode do not block and need no exclusion.

Check the exclusion on every new policy. A single missing exclusion is enough to make emergency access worthless.

Monitoring: every sign-in is an alert

Because these accounts are never used day to day, every sign-in is an event that must surface immediately. Microsoft recommends sending sign-in logs to a Log Analytics workspace and creating an alert rule that fires on any sign-in by the emergency accounts and notifies administrators by email or SMS.

Every use is followed by a short review: who used the account, why, and was the use justified?

Storage and regular testing

Credentials and security keys are stored separately in at least two secure locations, for example fireproof safes, and are accessible to several authorised people – never just one. They must not be tied to personal devices or expire automatically.

Microsoft recommends testing emergency access at least every 90 days, and after IT staff changes or changes to roles and subscriptions.

  • Is the list of authorised people current?
  • Does sign-in work with the current Conditional Access configuration?
  • Can administrative tasks be performed?
  • Does monitoring raise the alert?

Key takeaway

An emergency account that has never been tested is only an assumption when you need it. Two cloud accounts with passkeys, a clean Conditional Access exclusion, an alert on every sign-in and a test every 90 days turn it into reliable emergency access.

Sources