Keep two emergency Microsoft Entra accounts ready before the tenant needs them

Emergency access accounts provide a recovery path when normal administrators cannot sign in or activate a role. They must be independent, strongly protected, monitored, and tested without becoming everyday admin accounts.

Executive summary

What you need to know

Emergency access accounts provide a recovery path when normal administrators cannot sign in or activate a role. They must be independent, strongly protected, monitored, and tested without becoming everyday admin accounts.

Potentially affected

Microsoft Entra tenants, especially organizations that use federation, Conditional Access, Privileged Identity Management, multifactor authentication, or a small administrator team.

DSE recommendation

Maintain at least two cloud-only emergency accounts, protect them with independent phishing-resistant credentials, exclude them from blocking access policies, alert on use, and validate them every 90 days.

Source fact: what Microsoft documents

Microsoft recommends maintaining two or more emergency access accounts for situations in which ordinary administrators cannot sign in or activate a required role. Examples include an unavailable federated identity provider, inaccessible multifactor devices, an approval chain with no available approver, or an accidental tenant-wide lockout. These accounts are highly privileged and are intended only for planned validation or a real emergency.

The current Microsoft guidance says the accounts should be cloud-only, use the tenant’s .onmicrosoft.com domain, and have a permanent active Global Administrator assignment rather than an eligible assignment in Privileged Identity Management. Microsoft recommends phishing-resistant authentication with passkeys (FIDO2) or certificate-based authentication, credentials that do not share the same dependency as normal administrators, and designated secure workstations. Accounts should be excluded from Conditional Access policies that can block or restrict sign-in. Report-only policies do not block access and do not require that exclusion.

Microsoft also recommends alerting on every sign-in and audit event, keeping credentials in separate secure locations, reviewing every use, and validating account functionality at least every 90 days. A validation should prove that the account can sign in and perform an administrative task and that monitoring generates the expected notification.

Applicability and cautions

These recommendations apply to Microsoft Entra tenants, but the exact credential, alerting, workstation, storage, and approval design depends on the organization. Azure Monitor, Microsoft Sentinel, secure hardware, certificate infrastructure, or other components can introduce separate licensing and operational requirements. Emergency accounts must not be connected to employee-supplied devices or used as convenient secondary administrator identities.

DSE recommendation: production-safe operational steps

  1. Inventory existing emergency accounts, their object IDs, assigned roles, authentication methods, owners, storage locations, and policy exclusions.
  2. Create at least two cloud-only accounts if the tenant does not already have them. Use non-personal naming that does not expose a password or recovery detail.
  3. Register independent phishing-resistant credentials and store the credentials in separate, access-controlled locations available to more than one authorized custodian.
  4. Confirm permanent active Global Administrator assignment and exclude the accounts from every policy that could make them unusable during the failure scenario they address.
  5. Configure alerts for sign-in and audit activity, document authorized-use criteria, and require a post-use review.
  6. Run a witnessed drill at least every 90 days and after material administrator, authentication, federation, or Conditional Access changes.

DSE recommends recording the date, tester, observed alerts, administrative action, and any corrective work for each drill. Stop the test after the minimum administrative validation; do not use an emergency account for routine maintenance. If a test fails, treat the recovery design as unavailable until the cause is corrected and independently retested.

Official reference

Manage emergency access accounts in Microsoft Entra ID — account design, authentication, Conditional Access, monitoring, and validation guidance.

Primary reference

Review the official source

Microsoft Learn: Manage emergency access accounts in Microsoft Entra ID · Published June 5, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE