Emergency Access Accounts (Break Glass)

Ensuring Tenant Resilience During Outages or Breaches

Challenge

In the event of a breach or misconfiguration, the organization risked being locked out of its Microsoft Entra tenant. The goal was to implement secure, policy-compliant emergency access accounts to ensure business continuity and administrative recovery.

Tools & Technologies

Implementation

  1. Followed Microsoft’s emergency access guidance
  2. Created two break-glass accounts with Global Administrator roles
  3. Excluded accounts from Conditional Access and MFA policies
  4. Stored credentials securely in 1Password Vault with limited access
  5. Documented access procedures and escalation protocols
  6. Enabled alerting and auditing for any use of emergency accounts

Architecture Diagram

Break Glass Emergency Access Architecture Diagram Placeholder

Impact

  • Ensured administrative access during outages, breaches, or misconfigurations
  • Aligned with Microsoft’s security best practices for emergency access
  • Reduced risk of tenant lockout and improved operational resilience
  • Secured credentials with vault-based access control and auditability