Legal

Set up your break-glass admin account before you need it

On September 1, Microsoft started making passkeys the default sign-in method in Microsoft 365.

1 min readOriginally posted on LinkedIn

On September 1, Microsoft started making passkeys the default sign-in method in Microsoft 365, and the text-message and phone-call codes a lot of us still fall back on go away entirely on February 1, 2027.

Most firms will barely notice. The ones that will are the ones whose emergency administrator login depends on a text to somebody's phone.

Every Microsoft 365 tenant should have what we call a break-glass account — a separate admin login that exists for exactly one day: the day your normal admin can't get in. A security policy goes sideways and locks the office out. Your IT person is unreachable. Someone leaves on bad terms and you need control back this afternoon.

Here's what catches people. That account only helps if it was created before the emergency, tested since, and stored somewhere you can actually reach under pressure. A password in a drawer isn't a plan. Neither is a login tied to a phone number nobody carries anymore.

For a 15-attorney firm, a day locked out of email and documents isn't an IT problem. It's a day of billable hours you don't get back, plus the calls to clients explaining why nobody answered.

Microsoft's own guidance is at least two of these accounts, tested quarterly. Worth confirming yours exist and still work — well before February.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions