Session
Emergency Access done right – Setting up Microsoft 365 for success during disasters
Imagine this: it’s Monday morning and your administrators are locked out of Microsoft 365. A Conditional Access policy went wrong, authentication is failing, and your normal admin accounts can no longer get you back in. What’s your way back in?
This is where emergency access matters. But having a break-glass account is only the beginning. It needs to be securely designed, protected, monitored and regularly tested because the moment you need it is the worst possible time to discover that it doesn't work.
In this session, we explore why break-glass accounts are needed and how to design them so they remain available during an incident while minimizing the risk of misuse.
We’ll walk through real-world scenarios where normal administrative access can fail, and show how to build a secure emergency access strategy using Microsoft Entra ID and Microsoft security capabilities. This includes Restricted Management Administrative Units (RMAU), phishing-resistant authentication, and Microsoft Defender custom detection rules.
We’ll also look beyond the account itself and place break-glass access within a broader disaster recovery plan: how often should you test it? What tenant information should be securely stored in your vault? Who needs to be involved when emergency access is required? And how do you make sure the recovery process still works when you actually need it?
Jeffrey Tigchelaar-Moerbeek
Microsoft 365 Security & Modern Workplace Consultant, focused on identity and automation
Amsterdam, The Netherlands
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top