M365 Break Glass Accounts – full guide

๐Ÿ”’ย Secure Bits ๐Ÿ’ก

๐—•๐—ฟ๐—ฒ๐—ฎ๐—ธ-๐—ด๐—น๐—ฎ๐˜€๐˜€ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€: ๐—ณ๐˜‚๐—น๐—น ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒ (๐—ฃ๐——๐—™)

In my last post I talked about the โ€œworst dayโ€ scenario:ย CA misconfig โ†’ admins locked out. Most orgs think theyโ€™re coveredโ€ฆ until they test it.

As promised, ๐—ต๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜๐—ต๐—ฒ ๐—ณ๐˜‚๐—น๐—น ๐—ฃ๐——๐—™ ๐—ด๐˜‚๐—ถ๐—ฑ๐—ฒย that walks you through aย practical break-glass setup:

โ–ช๏ธ Naming

โ–ช๏ธ Permissions

โ–ช๏ธ Role-Assignable Security Group

โ–ช๏ธ Custom Break-glass Administrator role (Optional)

โ–ช๏ธ Restricted Management Administrative Unit (RMAU)

โ–ช๏ธ Authentication Methods

โ–ช๏ธ Conditional Access Configuration

โ–ช๏ธ Monitoring & Alerting

โ–ช๏ธ Operational Procedures

 

๐˜ˆ๐˜ถ๐˜ต๐˜ฉ๐˜ฐ๐˜ณ:ย Martin Strnad

๐Ÿ’ฌ When was the last time you tested your break-glass access?

 

๐Ÿ“Žย Download the PDF in this postย and keep it somewhere your team can actually find when things go sideways.