Skip to main content

Emergency Access Accounts

Every Microsoft 365 tenant keeps one or two emergency access accounts (break-glass) that let you back in when everything else is locked out. They are excluded from Conditional Access policies, they are not stopped by multi-factor authentication, and they usually go unused for years.

That is exactly what makes them the most valuable target an attacker has: nobody looks at them.

Controlio watches the sign-ins of the emergency access accounts you mark, and tells you when something unusual happens.

How you mark an account

Open the Emergency Access tab in the panel. Controlio lists the accounts in your tenant that could be candidates, with the reason for each:

  • accounts that exist only in the cloud, with no match in an on-premises directory
  • accounts excluded from Conditional Access policies
  • accounts whose name matches the emergency access naming pattern

It also tells you when an account cannot be one. An account whose role is granted temporarily through PIM, for instance, is unsuitable: in a real outage it may not be able to activate that role.

The candidate list is a suggestion; the decision is yours. Marking takes one click and can be undone at any time.

Do not mark an account you use daily

An emergency access account is idle by definition — unused for months. If you mark an account you use daily, every ordinary sign-in of yours raises an alert; you get dozens of notifications a day, and when something real happens that notification is lost among dozens that look just like it.

Controlio says so at the moment you mark it: if the candidate has signed in within the last seven days, the list carries a "appears to be in daily use" warning and the confirmation dialog states it at the top. It does not block you — it shows the evidence and leaves the decision to you.

Where we cannot read the sign-in record, we claim nothing; we do not present the account as idle.

What changes once you mark it

Sign-ins come under watch

Every sign-in on the account is watched, successful and failed alike. Password resets, changes to the multi-factor authentication method and the account being disabled also raise alerts.

The panel says plainly whether the watch is actually working: watch active, watch failing, or sign-ins cannot be watched. We do not present something we cannot read as protected.

This account stops receiving alert email

This matters and it is deliberate: when you mark an account as an emergency access account, it is removed from the AUTOMATIC recipient list for alerts.

Controlio alerts go to two sets of addresses: the Global Administrator and Security Administrator roles in your tenant (resolved automatically), and the addresses you enter by hand in settings. Marking affects only the automatic list. An address you entered yourself keeps receiving alerts even if its owner is marked as an emergency access account — you put that address there, and we do not drop it quietly. To remove it as well, delete it in settings.

The reason for removing it from the automatic list: if an attacker takes the account over, we do not want them reading the alerts that go out about themselves. In the panel these accounts carry a "Not an alert recipient" label.

This is why your tenant needs another administrator to receive the alerts. If you mark every administrator you have as an emergency access account, nobody is left to alert; Controlio watches for that state separately and tells you.

The phishing-resistant method is shown

You can see in the panel whether the account has a phishing-resistant sign-in method such as FIDO2 registered. If no such method is registered, that is stated too. Where we cannot read the methods, it says "could not be read" — we do not guess.

What happens under attack

A password attempt against an emergency access account is rarely a single event. An attacker keeps trying for hours, sometimes for days.

If we sent every attempt as its own email you would get dozens a day, and the one thing that actually matters — a successful sign-in — would be lost in the pile.

Instead, Controlio treats an ongoing run of attempts as a single campaign:

SituationWhat you get
Attempts have startedOne notification: the campaign is open
Attempts have risen sharplyOne further notification
Attempts continue over a long periodPeriodic status notifications
Attempts have stoppedA campaign-closed notification
A sign-in succeededA separate, prioritised notification — never grouped

A successful sign-in never blends into a campaign; it stands on its own and comes first.

Campaign notifications reduce the email, not the records. Every attempt is recorded individually, so you can go back later and ask when it started, how many attempts there were, and which address they came from.

Routine use of the account

An emergency access account is, as the name says, for emergencies. Once it starts being used for day-to-day work it loses the point: in a real incident, activity on that account looks ordinary.

If Controlio sees a marked account sign in successfully on three separate days within the last seven, it notes this in the panel. It is not an alert; it is a posture indicator.

Limits

To be straightforward about it:

  • The watch rests on Microsoft's sign-in logs. For any period where we cannot reach those logs, the panel says "cannot be watched"; we do not quietly show it as fine.
  • Microsoft scopes non-interactive sign-ins differently; what the panel measures holds only for the scope we can read.
  • Controlio watches these accounts, it does not block. It changes no setting and locks no account. Our access is read-only.