Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To keep administrative access during an identity-provider outage, configure at least two independent emergency accounts that do not rely on the identity system that has failed. For Microsoft Entra, Microsoft recommends cloud-only accounts on the tenant’s *.onmicrosoft.com domain, protected with phishing-resistant authentication, narrowly excluded from blocking Conditional Access policies, monitored on every use, and tested at least every 90 days.

This guide covers Microsoft Entra specifically. If you use another identity provider, follow its current official emergency-access instructions; Entra account types, roles, and policy controls do not automatically apply elsewhere.

Why emergency accounts need an independent sign-in path

A break-glass account is a contingency for authorized administrators who cannot use normal administrative sign-in. It can be especially important when sign-in depends on a federated identity provider that is unavailable. The emergency account must not depend on the same on-premises directory or federation path that caused the outage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s Microsoft Entra emergency-access guidance recommends creating two or more emergency access accounts. Use redundancy so a single unavailable account or credential does not eliminate the fallback.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Configure Microsoft Entra emergency accounts

  1. Create or identify two or more cloud-only accounts. Use accounts on the tenant’s *.onmicrosoft.com domain. Confirm they are not federated and are not synchronized from on-premises identity.
  2. Assign the Global Administrator role. If you use Microsoft Entra Privileged Identity Management (PIM), Microsoft says the emergency accounts’ assignments should be active and permanent, not merely eligible.
  3. Register phishing-resistant authentication before an incident. Microsoft recommends Passkey (FIDO2). Certificate-based authentication is also an option if your organization already operates the required PKI. Choose a method whose dependencies differ from ordinary administrator sign-in.
  4. Review Conditional Access policies. Exclude emergency accounts from policies that could block or restrict their sign-in, such as policies requiring MFA, a compliant device, or another control unavailable during the incident. Report-only policies do not block sign-in, so they do not need an exclusion. An exclusion from a blocking policy is not a reason to abandon strong authentication: Microsoft’s guidance calls for passwordless methods that satisfy mandatory MFA requirements.
  5. Prevent accidental loss of access. Ensure credentials and associated devices do not expire or get removed by inactivity cleanup. Limit use to authorized people, and use a designated secure administrative workstation or Privileged Access Workstation.
  6. Store credentials securely and redundantly. Microsoft recommends secure, fireproof storage in separate secure locations. A FIDO2 security key can be one physical credential option where supported; confirm compatibility with your tenant and credential policies. Do not make access depend on one employee’s personal device.
  7. Set up monitoring and alerts. Monitor sign-in and audit activity, and alert on every use. Also alert on account changes, including password changes, role or permission changes, and changes to credentials or authentication methods. Microsoft identifies Azure Monitor and Microsoft Sentinel as possible monitoring tools in Entra environments.
  8. Test the complete recovery path at least every 90 days. Schedule a drill, tell monitoring staff it is a test, review authorized users and procedures, verify staff readiness, test sign-in and administrative tasks, and confirm alerts fire. After actual use, conduct a post-incident review.

Choose an authentication method that survives the outage

The useful distinction is not simply which method is strongest on paper; it is whether the method is phishing-resistant and whether the organization can operate and securely distribute it without relying on the failed sign-in path.

Method Phishing resistance Dependency and readiness Practical consideration
Passkey (FIDO2) Recommended by Microsoft for emergency access. Register it before an incident and verify its dependency path is independent of normal administrator sign-in. A FIDO2 security key is a possible physical implementation; compatibility depends on identity provider, tenant configuration, and credential policy.
Certificate-based authentication Listed by Microsoft as an option; the guidance does not provide a comparative rating against FIDO2. Appropriate where the organization already operates PKI; ensure the certificate sign-in path remains available during the outage. Plan secure custody, distribution, and regular testing of the certificate and associated equipment.

Microsoft does not provide a head-to-head cost or performance comparison between these methods in the cited guidance. Avoid choosing a method whose issuance, validation, or required device depends on the identity service or infrastructure you are trying to survive.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Keep Conditional Access exclusions narrow

Emergency accounts may need exclusion from Conditional Access policies that block or restrict sign-in; otherwise, the policy itself could prevent recovery. Apply exclusions only to the emergency accounts and only where needed for access. Review the effective policies carefully so the exception does not spread to ordinary administrator accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Report-only policies do not block access and need no exclusion. Nor should an exclusion be treated as an exemption from strong authentication: configure the emergency sign-in method to meet applicable MFA requirements, following Microsoft’s emergency-access guidance.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Protect custody, detect use, and prove the process works

Emergency credentials must be available to multiple appropriate administrators without being casually accessible. Document who is authorized, where credentials are held, how an incident is declared, and how to reach the designated secure workstation. Keep the account itself out of inactivity cleanup, and protect the credentials and devices from expiry or routine removal.

  • Alert whenever an emergency account signs in.
  • Alert on password, role or permission, and authentication-method or credential changes.
  • During drills, verify both successful administrative access and the expected monitoring alerts.
  • After real use, review the incident and restore the emergency setup to its approved state.

Microsoft recommends validating emergency-account functionality at least every 90 days. A drill should exercise the whole path—from custody and staff readiness to sign-in, administrative work, and alert delivery—not merely confirm that an account exists.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changes for other identity providers?

The concrete account type, Global Administrator role, Conditional Access behavior, and testing details above are Microsoft Entra-specific. For Okta, Google Workspace, or another provider, consult that provider’s current official documentation for its emergency-access account model, policy exclusions, authentication requirements, alerting, and testing cadence. Do not assume an Entra configuration transfers directly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.