Scenario
An emergency admin account is deliberately excluded from MFA policies, yet login still fails during a real incident test.
Recommended Resolution Path
- Verify the exclusion is on the effective policy path and not shadowed by another rule.
- Check sign-in restrictions such as location, risk, or device requirements that still apply.
- Test the account on a known-clean browser session and document expected usage before an actual emergency.
- Treat a failed break-glass test as a serious operational gap and remediate immediately.
Technician Notes
Document what changed, what confirmed the fix, and whether the issue points to a broader standards gap worth addressing for the client.
- Log in to post comments
Subjects