Why emergency access matters
A Microsoft 365 tenant can become unreachable during an identity-provider outage, a Conditional Access mistake, or the loss of an administrator’s normal authentication method. Emergency-access accounts—often called break-glass accounts—provide a controlled route back into Microsoft Entra ID. They are not shortcuts for routine administration. They are tightly protected recovery tools.
Microsoft’s current guidance recommends maintaining at least two cloud-only emergency-access accounts, using the tenant’s onmicrosoft.com domain so they do not depend on federation or on-premises synchronization. Microsoft also recommends phishing-resistant authentication, secure storage, monitoring, and regular validation.
Build the accounts for independence
Create at least two emergency accounts that are not assigned to individual employees. Their credentials should not rely on the same phones, identity provider, network, or administrator workflow used every day. For small Central Florida businesses, this separation matters during hurricanes, power interruptions, vendor outages, and urgent personnel changes as much as it does during a cyberattack.
Use passkeys or FIDO2 security keys when practical. Store the credentials and hardware in separate, secure, fire-resistant locations accessible only to authorized leaders. Record who may retrieve them and under what circumstances.
Avoid locking out the recovery path
Conditional Access is essential, but a poorly scoped policy can block the very accounts intended to restore access. Microsoft advises excluding emergency-access accounts from policies that block or restrict sign-in while protecting them with phishing-resistant authentication. New Conditional Access rules should begin in report-only mode so administrators can study their expected impact before enforcement.
Do not weaken ordinary administrator protection to accommodate emergency accounts. Require phishing-resistant MFA for privileged roles, use least privilege for daily work, and reserve the break-glass identities for documented emergencies.
Monitor every use
An emergency account should be almost silent. Configure alerts for every sign-in and audit-log event involving it. An unexpected attempt deserves immediate investigation because the account holds unusually powerful privileges. Review account configuration, registered authentication methods, exclusions, and monitoring rules after any major tenant change.
Run a quarterly validation
A break-glass plan is only credible if it works. At least quarterly, an authorized administrator should verify that both accounts can authenticate from the designated secure workstation, reach the Entra administration portal, and complete a harmless validation step. Do not make production changes merely to prove access.
Record the date, tester, authentication method, result, and any corrective action. Confirm that credentials have not expired, devices remain available, alerts fired correctly, and current Conditional Access policies did not block access.
A management checklist
1. Maintain two or more cloud-only emergency-access accounts.
2. Use phishing-resistant credentials separate from normal administrator devices.
3. Exclude the accounts from policies that could block emergency sign-in.
4. Alert on every sign-in and audit event.
5. Store credentials in separate protected locations.
6. Test quarterly and after significant identity-policy changes.
7. Document authorization, retrieval, use, and post-event review.
For a Central Florida organization, this is a small but important continuity control. It helps leadership recover administrative access without turning a crisis into an improvised security exception.

