← Tutte le news
ARTICOLO
22 settembre 2026

FAQ MSP: break-glass / emergency access ≠ admin MFA extra

FAQ MSP: break-glass ≠ admin MFA extra. MS Learn emergency access + NIST AC-2 + OWASP MFA. Soft Auris m2m 3600 + tenant_id/aud @ 2026-09-22T06:37:25.174Z — postura, non cert. Distinto dalla FAQ offboarding 08:00.

Abbiamo già MFA su tutti gli admin MSP — ci servono ancora account break-glass?

Come dovrebbe un MSP dimostrare che gli account emergency Global Admin restano usabili sotto outage IdP/MFA senza diventare privilegio permanente non monitorato?

Cite (recuperate 22/09/2026): MS Learn emergency access (≥2 cloud-only .onmicrosoft.com; FIDO2/CBA phishing-resistant; escludere da CA bloccanti; GA permanente attiva in PIM; monitor + drill 90 giorni; post-mortem); NIST SP 800-53 Rev.5 AC-2 / AC-2(2); OWASP MFA Cheat Sheet; AWS SaaS Lens adiacenza cross-tenant.

MS Learn: gli account emergency access non sono “un admin MFA in più”. Usare ≥2 account cloud-only, auth phishing-resistant, escludere da Conditional Access che possano lockarli, tenere Global Admin permanente attiva in PIM, monitorare sign-in, fare drill ogni 90 giorni, scrivere post-mortem. NIST AC-2(2): account di emergenza attivati per crisi e disabilitati/rimossi automaticamente dopo un periodo definito dall'org. OWASP: i processi di MFA reset/bypass sono target per gli attaccanti — il recovery non deve indebolire l'MFA.

Postura soft Auris (isolamento prodotto, non una cert): m2m short-lived (lifetimeSeconds: 3600) + tenant_id/aud bound, probe ok, 0 violazioni @ 2026-09-22T06:37:25.174Z. Snapshot di postura prodotto osservata — non ACN, C5, SecNumCloud o CLOUD Act. Distinto dalla FAQ offboarding session-kill delle 08:00.

# MSP break-glass — not just another MFA admin
1. Provision ≥2 cloud-only .onmicrosoft.com emergency accounts (MS Learn)
2. Phishing-resistant auth (FIDO2/CBA); exclude from blocking Conditional Access
3. Permanent active Global Admin in PIM; monitor sign-ins
4. Run 90-day access drills + write post-mortems
5. NIST AC-2(2): activate for crisis; auto-disable after org-defined period
6. OWASP: MFA reset/bypass must not weaken MFA
7. Soft Auris posture: lifetimeSeconds 3600 + tenant_id/aud bound + 0 violations @ 2026-09-22T06:37:25.174Z — posture not cert
8. Ban: no ACN/C5/SecNumCloud/CLOUD Act claims
9. Distinct from 08:00 offboarding IdP-disable≠session-kill FAQ

Solo bozza. Pubblica l'umano. Soft Auris = postura di isolamento prodotto, non una certificazione. Nessuna claim ACN/C5/SecNumCloud/CLOUD Act. Distinto dalla FAQ offboarding 08:00.