Break-glass accounts should be boring, visible, and tested
Emergency access is not a checkbox. The useful design is small, monitored, excluded with intent, and exercised before an incident.
Emergency access accounts exist for the day normal identity controls stop working. That makes them both powerful and easy to neglect.
Minimize the exception
Keep the number of emergency accounts small. Give each one a clear owner, strong credentials, and an explicit reason for every policy exclusion. An account excluded from all controls without monitoring is not resilience; it is an unobserved privileged path.
Monitor use, not just sign-in failure
Alert on any sign-in attempt, credential change, role change, or authentication-method update involving an emergency account. Successful use should be rare enough that every event receives attention.
Exercise the path
A credential stored for years without validation is an assumption. Test the documented access procedure on a controlled schedule and record what happened. Current Microsoft guidance should remain the source of truth for authentication-method and Conditional Access details.