Should I Enable MFA for Emergency Accounts?

0
13
Asked By TechNinja42 On

I'm seeking advice on whether to set up multi-factor authentication (MFA) for our emergency accounts in Entra. We've established two emergency accounts with OTP and two Yubikeys configured for MFA. However, our current MFA conditional access policies exclude these emergency accounts as per Microsoft's guidance. While I'll be implementing login alerts, I'm feeling uneasy about not enforcing MFA on accounts that have Global Administrator access. Is this truly the best practice?

5 Answers

Answered By CloudHero99 On

You should really think about whether MFA would still work when you need to use the emergency account. That’s the critical point to consider here.

Answered By SecureAdmin88 On

I’ve noticed you already have MFA with OTP and Yubikeys. Personally, I'd suggest sticking with just the Yubikeys and dropping the OTP for better security.

Answered By RiskAwareJoe On

In my experience, any account with elevated privileges should definitely have two-factor authentication. Remember, Microsoft won’t be responsible if your account gets compromised.

Answered By SafetyFirst123 On

Consider setting up the accounts to work exclusively with Yubikeys—meaning no OTP or password required. By ensuring a physical token is mandatory for login, the lack of MFA might not pose a significant risk.

Answered By PasswordNerd101 On

The Microsoft guidelines actually recommend against using MFA on those emergency accounts—just aim for a strong, complex password instead.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.