-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Microsoft Identity and Access Administrator SC-300 Exam Guide
By :

While it’s critical to ensure the security of our identities with features such as MFA, Conditional Access policies, entitlement management, and PIM, it’s also crucial to prevent accidental lockout from Entra ID. To safeguard against these scenarios and ensure access during emergencies, you should configure at least two emergency-access accounts, commonly referred to as break-glass accounts.
These accounts, which have Global Administrator privileges, allow quick access to resources when other administrator accounts are locked out. They should also be excluded from all Conditional Access policies. The use of these accounts should be strictly limited to emergency situations, and their credentials should be securely stored, such as in a password vault, until needed and then reset after use. A strong authentication method should be enabled, such as a FIDO2 security token.
Break-glass accounts are directly linked to the Entra...