Entra ID & IdentityHow-To & HardeningRetrospectives

How to Create and Monitor Break-Glass Emergency Access Accounts in Entra ID

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in fails. Here is how to set them up and monitor them.

Step 1: Create two cloud-only accounts

  • Use the .onmicrosoft.com domain so they don't depend on federation or on-premises infrastructure.
  • Assign the Global Administrator role permanently (not via PIM activation, which could fail during an outage).
  • Do not assign them to a specific person or give them a mailbox used for anything else.

Step 2: Choose strong authentication

Microsoft now enforces MFA for admin portals, so break-glass accounts need an MFA method that doesn't depend on the same systems that might fail. The recommended approach is FIDO2 security keys or passkeys, stored securely in separate locations. Keep the long, random password split or stored in a secure physical location as well.

Step 3: Handle Conditional Access carefully

Exclude at least one break-glass account from Conditional Access policies that could lock everyone out (for example, compliant-device or location policies), while still requiring phishing-resistant MFA where possible. Document every exclusion.

Step 4: Monitor every sign-in

Create an alert that fires on any sign-in by these accounts:

SigninLogs
| where UserPrincipalName in~ ("[email protected]", "[email protected]")

Route it to multiple people. Any unplanned use is a security incident.

Step 5: Test regularly

Test sign-in for each account every 90 days and after major identity changes. Record the test.

Step 6: Document the procedure

Who can retrieve the credentials, how, and what they must do afterwards (rotate, review, report).

break glass account entra idAzure MFA outage2018

More on this story