How to Create and Monitor Break-Glass Emergency Access Accounts in Entra ID
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in fails. Here is how to set them up and monitor them.
Step 1: Create two cloud-only accounts
- Use the
.onmicrosoft.comdomain so they don't depend on federation or on-premises infrastructure. - Assign the Global Administrator role permanently (not via PIM activation, which could fail during an outage).
- Do not assign them to a specific person or give them a mailbox used for anything else.
Step 2: Choose strong authentication
Microsoft now enforces MFA for admin portals, so break-glass accounts need an MFA method that doesn't depend on the same systems that might fail. The recommended approach is FIDO2 security keys or passkeys, stored securely in separate locations. Keep the long, random password split or stored in a secure physical location as well.
Step 3: Handle Conditional Access carefully
Exclude at least one break-glass account from Conditional Access policies that could lock everyone out (for example, compliant-device or location policies), while still requiring phishing-resistant MFA where possible. Document every exclusion.
Step 4: Monitor every sign-in
Create an alert that fires on any sign-in by these accounts:
SigninLogs
| where UserPrincipalName in~ ("breakglass1@contoso.onmicrosoft.com", "breakglass2@contoso.onmicrosoft.com")
Route it to multiple people. Any unplanned use is a security incident.
Step 5: Test regularly
Test sign-in for each account every 90 days and after major identity changes. Record the test.
Step 6: Document the procedure
Who can retrieve the credentials, how, and what they must do afterwards (rotate, review, report).
- The Azure AD MFA Outage of November 2018: When Sign-In Itself Goes Down Incident Teardowns
- Identity Outage Runbook: What to Do When MFA Is Down How-To & Hardening
- CIO Brief: Planning for the Day Your Identity Provider Is Unavailable CIO Briefings