Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Planning for the Day Your Identity Provider Is Unavailable

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and cloud apps for hours. Security that depends on one service fails when that service fails.

Why identity needs a resilience plan

Requiring multi-factor authentication for everyone is the right decision. But it means your identity provider becomes a single point of failure for the whole business. Outages are rare, but they happen to every provider.

The business impact

  • Productivity loss across the company.
  • Administrators locked out when they need access most.
  • Risky improvisation, like disabling security controls in a hurry and forgetting to turn them back on.

Questions to ask your team

  • Do we have emergency administrator accounts that would work during an outage, and when were they last tested?
  • How would we communicate with employees if email and Teams were unavailable?
  • Who is authorized to relax security controls during an outage, and how are those changes reversed?

What good looks like

Two tested emergency access accounts with strong, independent protection, a short outage runbook, an out-of-band communication channel, and clear authority for temporary changes.

The decision

Ask when your emergency access accounts were last tested. If nobody knows, schedule a test this month — it takes less than an hour.

azure mfa outage impactAzure MFA outage2018

More on this story