I'm putting together a disaster-recovery plan for a Microsoft tenant deauthentication or outage scenario. The difficult case is Entra-joined, Intune-managed workstations: if normal workstation sign-in fails and Intune is unavailable, we may not be able to retrieve the LAPS password. What is the recommended recovery process, and how long can users continue signing in with cached credentials?
2 Answers
Maintain a separately documented, tested local administrator break-glass account for this scenario. Its credentials should be controlled through a secure process and protected carefully, but it must not depend on Entra ID, Intune, or the tenant being reachable. Otherwise the recovery method has the same dependency as the outage.
Make sure the incident plan also includes an established Microsoft support escalation path and a tested tenant-recovery procedure. Before an outage, validate cached sign-in behavior, local-admin access, device recovery options, and how credentials will be obtained if Intune cannot be contacted.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures