how to exempt break glass account from AAD free when default security is turned on?

Betty Stolwyk 70 Reputation points
2023-03-30T03:16:30.97+00:00

We have the free Azure AD license. We received the notification that default Security will be turned on in about 10 days. From what I understand that forces MFA for ALL users. We have, however, the recommended break glass emergency account which should be exempt from MFA. Is there a way to do that without using conditional access (which we do not have.)

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,701 questions
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 35,456 Reputation points Microsoft Employee
    2023-03-30T03:54:23.8266667+00:00

    @Betty Stolwyk Thank you for reaching out to us, As I understand you want to exempt emergency access accounts (break glass) from MFA, researched on your requirement in order to exclude the break glass account from MFA only option we have is to exclude via Conditional access - https://learn.microsoft.com/en-us/azure/active-directory/roles/security-emergency-access#:~:text=Exclude%20at%20least%20one%20account%20from%20Conditional%20Access%20policies

    Also, you might be aware conditional access comes with P1 or P2 license - https://www.microsoft.com/en-us/security/business/identity-access/azure-active-directory-pricing

    However as @Dillon Silzer shared in his answer reference article - https://janbakker.tech/break-glass-accounts-and-azure-ad-security-defaults/ where they mentioned to use FIDO key to break glass account, but there is a limitation to it if accidentally someone deletes the FIDO2 key from the account without knowing, then we will have a challenge in accessing the Azure AD resources when we really need it.

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Dillon Silzer 57,686 Reputation points
    2023-03-30T03:54:36.04+00:00

    Hello Betty,

    Please refer to this guide for creating a break glass account for Azure AD with security defaults enabled:

    Break glass accounts and Azure AD Security Defaults

    https://janbakker.tech/break-glass-accounts-and-azure-ad-security-defaults/



Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.