Required for the site to work (login, preferences, security). Always on.
MSP FAQ: break-glass emergency access ≠ extra MFA admin
MSP FAQ: break-glass ≠ extra MFA admin. MS Learn emergency access + NIST AC-2 + OWASP MFA. Soft Auris m2m 3600 + tenant_id/aud @ 2026-09-22T06:37:25.174Z — posture not cert. Distinct from 08:00 offboarding FAQ.
We already MFA all MSP admins — do we still need break-glass accounts?
How should an MSP prove emergency Global Admin accounts stay usable under IdP/MFA outage without becoming unmonitored standing privilege?
Cite (fetched 2026-09-22): MS Learn emergency access (≥2 cloud-only .onmicrosoft.com; phishing-resistant FIDO2/CBA; exclude from blocking CA; permanent active GA in PIM; monitor + 90-day drills; post-mortem); NIST SP 800-53 Rev.5 AC-2 / AC-2(2); OWASP MFA Cheat Sheet; AWS SaaS Lens cross-tenant adjacency.
MS Learn: emergency access accounts are not “one more MFA'd admin.” Use ≥2 cloud-only accounts, phishing-resistant auth, exclude from Conditional Access that could lock them out, keep permanent active Global Admin in PIM, monitor sign-ins, run 90-day drills, write post-mortems. NIST AC-2(2): emergency accounts activated for crisis use and automatically disabled/removed after an org-defined period. OWASP: MFA reset/bypass processes are attacker targets — recovery must not weaken MFA.
Soft Auris posture (product isolation, not a cert): short-lived m2m (lifetimeSeconds: 3600) + tenant_id/aud bound, probe ok, 0 violations @ 2026-09-22T06:37:25.174Z. Observed product posture snapshot — not ACN, C5, SecNumCloud, or CLOUD Act. Distinct from the 08:00 offboarding session-kill FAQ.
# MSP break-glass — not just another MFA admin
1. Provision ≥2 cloud-only .onmicrosoft.com emergency accounts (MS Learn)
2. Phishing-resistant auth (FIDO2/CBA); exclude from blocking Conditional Access
3. Permanent active Global Admin in PIM; monitor sign-ins
4. Run 90-day access drills + write post-mortems
5. NIST AC-2(2): activate for crisis; auto-disable after org-defined period
6. OWASP: MFA reset/bypass must not weaken MFA
7. Soft Auris posture: lifetimeSeconds 3600 + tenant_id/aud bound + 0 violations @ 2026-09-22T06:37:25.174Z — posture not cert
8. Ban: no ACN/C5/SecNumCloud/CLOUD Act claims
9. Distinct from 08:00 offboarding IdP-disable≠session-kill FAQ
Draft only. Human publishes. Soft Auris = product isolation posture, not a certification. No ACN/C5/SecNumCloud/CLOUD Act. Distinct from 08:00 offboarding FAQ.