The settingWhat we hold this to
CreativeTechs minimum
Exactly one break-glass account: cloud-only on the .onmicrosoft.com domain, Global Administrator, NO mailbox, NO licence, excluded from every CA policy, passphrase ≥ 24 characters split across two vault entries, and a sign-in alert wired to the team. Total Global Admins in the tenant: 2 to 4.
Benchmark position
Huntress: 'Between two and four Global Administrators are designated' (High). Microsoft Secure Score OneAdmin awards for more than one. Our minimum adds the mailbox-free and CA-exclusion requirements, which neither states explicitly.
Where we differ, and why
We are stricter than the published guidance: it counts admins, we also require the break-glass account carry no mailbox and no day job.
Where the switch is
Entra admin centre → Identity → Users → New user (cloud-only). Then Protection → Conditional Access → each policy → Users → Exclude. Alerting: Entra → Monitoring → Alerts, or a sign-in log rule.
How to verify
Graph: /directoryRoles → Global Administrator members; cross-check each against /users?$select=assignedLicenses,mail
- Why it matters
- A CA misconfiguration or an MFA outage locks out everyone, us included. A break-glass account carrying a mailbox and a day job is not a break-glass account.
- How we check
- Maester MT.1005 (CA exclusion), MT.1028 (role assignment). Secure Score OneAdmin.
- Fix — M365
- One cloud-only account on the .onmicrosoft.com domain, Global Admin, no mailbox or licence, excluded from every CA policy, long random passphrase split across the vault, sign-in alert to the team.
- Fix — Google
- One super-admin, no mail routing, recovery details recorded off-platform.
- User notices
- None.
- Expected pushback
- None from clients — but this fails on our own tenant today. Two accounts named Tim Pearson, both tenant-wide roles, both mailbox-enabled, one auto-detected as the emergency account. Fix ours first; it's the demo.
