๐ Secure Bits ๐ก
๐ฌ๐ผ๐๐ฟ ๐๐ฒ๐ป๐ฎ๐ป๐ ๐ต๐ฎ๐ ๐๐ ๐บ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป. ๐๐๐ฒ๐ฟ๐ ๐ฎ๐ฑ๐บ๐ถ๐ป ๐ถ๐ ๐น๐ผ๐ฐ๐ธ๐ฒ๐ฑ ๐ผ๐๐. ๐๐ผ ๐๐ผ๐ ๐ต๐ฎ๐๐ฒ ๐ฎ ๐๐ฎ๐ ๐ฏ๐ฎ๐ฐ๐ธ ๐ถ๐ป?
Most organizations donโt โ or think they do, until they discover their break-glass accounts are untested, unmonitored, or built on outdated guidance. You donโt want to find that out the hard way, and you definitely donโt want to go through Microsoftโs Tenant Recovery process.
๐ค ๐ช๐ต๐ ๐ฐ๐ฎ๐ฟ๐ฒ?
A lockout from a bad CA policy, a compromised admin, or a personnel emergency means opening a support ticket with Microsoft and waiting. In urgent situations, you donโt have 14 days for that process.
๐ง ๐ช๐ต๐ฎ๐ ๐๐ฒ ๐๐ฒ๐ฒ ๐ถ๐ป ๐๐ต๐ฒ ๐ณ๐ถ๐ฒ๐น๐ฑ
โข๐๐ฟ๐ฒ๐ฎ๐ธ-๐ด๐น๐ฎ๐๐ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐ ๐ฎ๐ฟ๐ฒ ๐บ๐ถ๐๐๐ถ๐ป๐ด โ Two geographically separated accounts is the baseline.
โข๐๐ฒ๐ป๐ฒ๐ฟ๐ถ๐ฐ ๐ป๐ฎ๐บ๐ฒ๐ โ admin@โฆ, info@โฆ are not break-glass accounts.
โข๐๐๐น๐น ๐๐ ๐ฒ๐
๐ฐ๐น๐๐๐ถ๐ผ๐ป ๐ถ๐ ๐ฑ๐ฒ๐ฎ๐ฑ โ MFA is now enforced by Microsoft regardless.
โข๐ช๐ฒ๐ฎ๐ธ ๐ฎ๐๐๐ต ๐บ๐ฒ๐๐ต๐ผ๐ฑ๐ โ Phone or certificate-based auth will fail exactly when you need it.
โข๐จ๐ป๐ฝ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ฒ๐ฑ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐ โ Any admin can edit or delete them.
โข๐ก๐ผ ๐บ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด โ If someone touches these accounts, you should know immediately.
๐ ๏ธ ๐๐ฟ๐ฒ๐ฎ๐๐ฒ ๐๐๐ผ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐
Use descriptive names on onmicrosoft[.]com with a random string โ e.g. BreakGlass_c3287ba1@org.onmicrosoft.com. Assign ๐๐น๐ผ๐ฏ๐ฎ๐น ๐๐ฑ๐บ๐ถ๐ป๐ถ๐๐๐ฟ๐ฎ๐๐ผ๐ฟ as a direct, permanent, active role. No eligibility.
๐ ๏ธ ๐๐ผ๐ฐ๐ธ ๐๐ต๐ฒ๐บ ๐ฑ๐ผ๐๐ป
Place both accounts and their group inside an ๐ฅ๐ ๐๐จ (requires Entra P1). Manage access via a custom PIM role โ max 1-hour activation, approval required, auth context enforced (requires Entra P2).
๐ ๏ธ ๐๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ ๐ฎ๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป
Scope a passkey profile to the break-glass group with specific AAGUIDs for your hardware keys (YubiKey, Token2). Enforce via a custom authentication strength in a dedicated CA policy. Exclude the group from all other CA policies โ run a What If to verify only your two break-glass policies apply.
๐ ๏ธ ๐ฆ๐ฒ๐ ๐๐ฝ ๐ฎ๐น๐ฒ๐ฟ๐๐ถ๐ป๐ด
Stream AuditLogs and SignInLogs to a Log Analytics Workspace (requires Azure subscription). KQL alert rule on the break-glass Object IDs โ any event fires immediately.
๐ก๏ธ ๐ฆ๐๐ผ๐ฟ๐ฒ, ๐๐ฒ๐๐, ๐ฑ๐ผ๐ฐ๐๐บ๐ฒ๐ป๐
Each passkey PIN in a separate physical location. Define who can trigger the procedure and under what circumstances. Test end-to-end at minimum every 180 days โ Microsoft recommends 90. Pick your cadence, but validate.
๐ฌ When was the last time you tested these accounts?
๐๐ถ๐๐ฉ๐ฐ๐ณ: Martin Strnad
PS: We will soon ๐ฝ๐๐ฏ๐น๐ถ๐๐ต ๐ณ๐๐น๐น ๐ด๐๐ถ๐ฑ๐ฒ on this topic!
#EntraID #IdentitySecurity #ConditionalAccess #SecureBits #HorizonSecured