← Alle News
ARTIKEL
22. September 2026

MSP-FAQ: Break-Glass-Notfallzugang ≠ extra MFA-Admin

MSP-FAQ: Break-Glass ≠ Extra-MFA-Admin. MS Learn Emergency Access + NIST AC-2 + OWASP MFA. Soft-Auris m2m 3600 + tenant_id/aud @ 2026-09-22T06:37:25.174Z — Posture, kein Zert. Getrennt von 08:00-Offboarding-FAQ.

Alle MSP-Admins haben schon MFA — brauchen wir trotzdem Break-Glass-Konten?

Wie soll ein MSP beweisen, dass Emergency-Global-Admin-Konten bei IdP-/MFA-Ausfall nutzbar bleiben, ohne unüberwachtes Standing Privilege zu werden?

Quellen (abgerufen 22.09.2026): MS Learn Emergency Access (≥2 cloud-only .onmicrosoft.com; phishing-resistente FIDO2/CBA; von blockierenden CA ausschließen; permanent aktiver GA in PIM; Monitor + 90-Tage-Drills; Post-Mortem); NIST SP 800-53 Rev.5 AC-2 / AC-2(2); OWASP MFA Cheat Sheet; AWS SaaS Lens Cross-Tenant-Adjazenz.

MS Learn: Emergency-Access-Konten sind nicht „noch ein MFA-Admin“. ≥2 Cloud-only-Konten, phishing-resistente Auth, von sperrenden Conditional Access ausnehmen, permanenten aktiven Global Admin in PIM halten, Sign-ins monitoren, 90-Tage-Drills, Post-Mortems. NIST AC-2(2): Notfallkonten für Krisennutzung aktiviert und nach org-definierter Periode automatisch deaktiviert/entfernt. OWASP: MFA-Reset-/Bypass-Prozesse sind Angreiferziele — Recovery darf MFA nicht schwächen.

Soft-Auris-Posture (Produktisolation, kein Zert): short-lived m2m (lifetimeSeconds: 3600) + tenant_id/aud gebunden, Probe ok, 0 Violations @ 2026-09-22T06:37:25.174Z. Beobachteter Produkt-Posture-Snapshot — kein ACN, C5, SecNumCloud oder CLOUD Act. Getrennt von der 08:00-Offboarding-Session-Kill-FAQ.

# MSP break-glass — not just another MFA admin
1. Provision ≥2 cloud-only .onmicrosoft.com emergency accounts (MS Learn)
2. Phishing-resistant auth (FIDO2/CBA); exclude from blocking Conditional Access
3. Permanent active Global Admin in PIM; monitor sign-ins
4. Run 90-day access drills + write post-mortems
5. NIST AC-2(2): activate for crisis; auto-disable after org-defined period
6. OWASP: MFA reset/bypass must not weaken MFA
7. Soft Auris posture: lifetimeSeconds 3600 + tenant_id/aud bound + 0 violations @ 2026-09-22T06:37:25.174Z — posture not cert
8. Ban: no ACN/C5/SecNumCloud/CLOUD Act claims
9. Distinct from 08:00 offboarding IdP-disable≠session-kill FAQ

Nur Entwurf. Mensch publiziert. Soft Auris = Produktisolations-Posture, keine Zertifizierung. Keine ACN-/C5-/SecNumCloud-/CLOUD-Act-Claims. Getrennt von 08:00-Offboarding-FAQ.