Skip to content
HOME / AZURE / MICROSOFT ENTRA ID (AZURE 3 years AGO

Azure

Microsoft Entra ID (Azure AD) Break Glass Account: Best Practices

Microsoft Entra ID (Azure AD) Break Glass Account: Best Practices

Last Updated on August 13, 2025 by Arnav Sharma

Glass Break Accounts also known as emergency access accounts, are a failsafe, designed to ensure that administrators can always gain access to the Azure AD tenant, even when normal admin accounts can’t sign in due to an unforeseen event.

The Role of Break Glass Accounts in Microsoft Azure

A Break Glass account in Azure AD is a special type of administrative account that is intended for use in emergency scenarios where the regular MFA service is not operational, or when conditional access policies prevent standard sign-in procedures. These accounts are highly privileged and are typically excluded from policies that apply to non-emergency accounts.

Best Practices for Managing Emergency Access Accounts in Azure AD (Microsoft Entra ID)

When setting up Break Glass accounts, Microsoft recommends adhering to certain best practices to secure the account effectively:

  1. Cloud-Only Accounts

    • Why Cloud-Only? Cloud-only accounts are not affected by on-premises directory changes, ensuring uninterrupted emergency access.
    • Best Practice Implementation: Create these accounts directly in the Azure portal, ensuring they remain entirely separate from any on-premises synchronization processes.
  2. Exclusion from Policies

    • The Need for Exclusion: To guarantee access during an emergency, Break Glass accounts must bypass Conditional Access and MFA.
    • Best Practice Implementation: Place Break Glass accounts in an Azure AD group that is excluded from all Conditional Access policies and ensure they are not enrolled in MFA.
  3. Password Management

    • Complexity and Security: Use complex passwords that are less prone to brute-force attacks and ensure they are securely managed.
    • Best Practice Implementation: Utilize a password manager for generating and storing complex passwords, and set these accounts to have non-expiring passwords.
  4. Limited Use

    • Restricting Usage: Limit the use of Break Glass accounts to emergency situations only to prevent misuse.
    • Best Practice Implementation: Establish and enforce policies detailing the specific conditions under which these accounts can be used.
  5. Dual Accounts

    • Redundancy is Key: Maintain at least two Break Glass accounts to ensure that one is always available if the other is compromised.
    • Best Practice Implementation: Securely store credentials for multiple accounts in different locations and ensure they are both tested regularly.
  6. Monitoring

    • Proactive Oversight: Continuously monitor these accounts to detect unauthorized use and respond to alerts.
    • Best Practice Implementation: Set up Azure Log Analytics to track account activity and configure Azure Monitor alert rules to notify designated personnel of any account usage.
  7. Testing

    • Ensuring Readiness: Regularly test Break Glass accounts to confirm they are operational and can provide access when needed.
    • Best Practice Implementation: Include Break Glass account testing in routine security exercises, documenting each test and updating procedures based on the findings.

Azure AD Identity and Security Defaults

While Azure AD Security Defaults provide a robust level of security by enforcing MFA through methods like the Microsoft Authenticator app, Break Glass accounts must be able to bypass these controls. This is where Azure AD Identity Protection comes into play, allowing the configuration of these accounts to ensure they remain accessible in emergencies.

Monitoring with Azure Log Analytics and Microsoft Sentinel

To manage emergency access admin accounts effectively, it’s recommended to connect Azure AD sign-in and audit logs with a created Log Analytics workspace. This allows for comprehensive monitoring and analysis of Break Glass account usage. Additionally, integrating with Microsoft Sentinel can provide advanced threat detection and response capabilities.

Azure AD Break Glass accounts are a critical component of a resilient Microsoft Azure security strategy. They provide a necessary backdoor for administrators to use Azure AD and manage emergency situations effectively. By following the best practices for creating and managing these accounts, organizations can ensure that their Azure AD tenant remains secure and accessible, even in the most challenging circumstances.

Arnav Sharma
Arnav Sharma Microsoft MVPMCT
Microsoft Certified Trainer · Cloud · Cybersecurity · AI

I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.

Frequently Asked Questions

KEEP READING

Machine Identities in Azure

Last Updated on June 23, 2026 by Arnav Sharma As an architect who has spent years helping organisations rebuild their Azure identity…

2026.06.23 · 11 MIN READ

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.