EIDCA-006: Break-Glass Account CA Exclusion Validation

Platform
Entra ID / M365
Category
Entra ID Conditional Access
Severity
Critical
Zero Trust pillar
Identity (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Emergency access (break-glass) accounts must be excluded from Conditional Access policies to ensure access during outages or misconfigurations, but these exclusions must be tightly controlled. Failure to properly configure break-glass exclusions can result in complete lockout during critical incidents or create unmonitored backdoor accounts.

Recommended value

Exactly two break-glass accounts excluded from all CA policies with monitoring, alerts, and regular validation

Remediation

Verify that dedicated break-glass accounts exist, are excluded from all Conditional Access policies, and are not used for daily operations. Configure Azure Monitor alerts to trigger on any sign-in activity from break-glass accounts. Test break-glass account access quarterly and store credentials securely in a physical safe or hardware security module.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDCA-006
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
AC-2(2)
CIS M365 Benchmark
1.1.4
MITRE ATT&CK
T1078.004