Skip to content
← Back to the guide

Conditional Access break-glass account design

4slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 4

Conditional Access break-glass account design

How to design break-glass accounts that survive every Conditional Access disaster — credentials, monitoring, and recovery.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/conditional-access-break-glass

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 4
01

Why should break-glass accounts be excluded from Conditional Access?

Because the scenario they exist for is a Conditional Access, MFA, or federation failure that locks every other admin out. A break-glass account subject to the same policies fails the same way. Exclude them from all ordi…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/conditional-access-break-glass

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 4
02

Should break-glass accounts be cloud-only?

Yes. Synced accounts depend on Entra Connect and on-premises AD; federated accounts depend on the federation service. A break-glass account must sign in when any of those are broken, so it is created directly in Entra I…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/conditional-access-break-glass

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 4
03

How do I know if someone used the break-glass account?

Alert on every sign-in. Send sign-in logs to Log Analytics or Sentinel and create an alert rule for the account's UPN that fires on any successful or failed sign-in, routed to the security lead's phone. Test it quarterl…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/conditional-access-break-glass

Slide 4Download PNG

Auto-generated from Conditional Access break-glass account design. This page is not indexed and isn't part of the guide itself.