Entra ID & IdentityHow-To & HardeningRetrospectives

Identity Outage Runbook: What to Do When MFA Is Down

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.

1. Confirm the outage

  • Check the Microsoft 365 Service health dashboard and the Azure status page (if you can reach them).
  • Check Microsoft's public status channels for updates.
  • Confirm whether the issue is tenant-wide, regional or limited to one method (for example SMS).

2. Declare and communicate

  • Declare an incident and assign an incident lead.
  • Notify staff through a channel that doesn't depend on Microsoft 365 sign-in (SMS, a status page, phone tree).
  • Tell the help desk what to say.

3. Decide on workarounds

  • Wait if Microsoft expects recovery soon and existing sessions keep working.
  • Use break-glass accounts only if administrative action is essential.
  • Do not disable MFA tenant-wide unless leadership explicitly accepts the risk, and if you do, set a timer to restore it.

4. If you change settings

  • Record every change, who made it and when.
  • Prefer narrow changes (one group, one method) over broad ones.
  • Monitor sign-in logs closely while controls are relaxed.

5. Recovery

  • Reverse every temporary change.
  • Rotate break-glass credentials if used.
  • Review sign-ins during the outage window for suspicious activity.

6. Afterwards

  • Hold a short review.
  • Update this runbook.
  • Consider whether more users need a second, independent MFA method registered.
identity outage runbook checklistAzure MFA outage2018

More on this story