{"id":1007793,"date":"2026-06-01T12:11:37","date_gmt":"2026-06-01T10:11:37","guid":{"rendered":"https:\/\/www.teal-consulting.de\/2026\/06\/01\/microsoft-entra-break-glass-best-practices\/"},"modified":"2026-06-01T14:59:17","modified_gmt":"2026-06-01T12:59:17","slug":"microsoft-entra-break-glass-best-practices","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2026\/06\/01\/microsoft-entra-break-glass-best-practices\/","title":{"rendered":"Emergency Access in Microsoft Entra: Best Practices for Your Break-Glass Accounts"},"content":{"rendered":"<div class=\"wpb-content-wrapper\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text][\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]Imagine it\u2019s Tuesday morning at 9:00 a.m. A routine update to your Conditional Access policies in Microsoft Entra goes wrong. A small logical error, a checkbox set incorrectly in the exclusions, and suddenly you and your entire admin team are locked out of the tenant. No access to Microsoft 365, no Azure management, completely unable to act.<\/p>\n<p>Emergencies happen every day. Most of the time, they affect other people. Until the day it happens to your own company. What do you do then?<\/p>\n<p>At TEAL, we know from our daily consulting work: Most IT managers know in theory that things can go wrong. But hardly any company invests enough time in planning for the scenario of losing total control over its own cloud environment. That\u2019s understandable\u2026 until a misconfiguration, a global system failure, or a targeted cyberattack turns that theoretical problem into a very real reality.<\/p>\n<p>This is exactly where emergency accounts\u2014so-called \u201cbreak-glass accounts\u201d\u2014come into play. In this article, we\u2019ll show you how to securely set up, harden, and monitor this last line of defense in Microsoft Entra according to current best practices.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>The harsh reality in many server rooms<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]On paper, the need for emergency access is an absolute no-brainer for any Identity and Access Management (IAM) expert. However, when we look at the reality in companies, from small and medium-sized businesses (SMBs) to large corporations, we usually encounter one of three nightmare scenarios:<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li><strong>There are simply no break-glass accounts at all<\/strong><\/li>\n<li><strong>There is an emergency account,<\/strong> but it was created years ago by a former employee, the password is nowhere to be found, and a login has never been tested<\/li>\n<li><strong>Accounts exist,<\/strong> but there is no documentation and no emergency manual<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]To make matters worse, the technical landscape is changing rapidly. Microsoft\u2019s Secure Future Initiative now strictly enforces multi-factor authentication (MFA) for admin portals and CLI tools. The outdated approach of simply creating an emergency account with a 30-character password and exempting it from any MFA no longer works technically and is extremely dangerous. Your break-glass setup shouldn\u2019t be a static document sitting in a drawer; it needs to be dynamic.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Break-Glass Accounts \u201eDone Right\u201c<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]A \u201cbreak-glass\u201d account in Microsoft Entra ID is a standalone account assigned the Global Administrator role. It is not linked to any specific individual. Why? Because, in an emergency, access must not depend on whether a particular employee is on vacation, sick, or even still employed by the company.<\/p>\n<p>To protect these accounts as critical infrastructure, we recommend the following procedure:<\/p>\n<h3>1. Title: Put an End to \u201cSecurity by Obscurity\u201d<\/h3>\n<p>It used to be commonly believed that emergency accounts should have inconspicuous names so as not to attract attention during reconnaissance by attackers. This way of thinking is outdated. Attackers aren\u2019t looking for names; they\u2019re looking for permissions.<\/p>\n<p><strong>Our recommendation:<\/strong> <span style=\"color: #008081;\"><em>\u201cUse clear, unambiguous names (e.g., BreakGlass01@ihrefirma.onmicrosoft.com) and use only the standard .com domain. In an emergency, your own SOC team and admins need to be able to identify which account is involved immediately and without any guesswork,\u201d<\/em><\/span> says our Security Architect Fabian B\u00f6hm.<\/p>\n<p>&nbsp;<\/p>\n<h3>2. Permissions: Permanent and active<\/h3>\n<p>The emergency account must be operational immediately when everything else fails. Therefore, this role must not be requested via Privileged Identity Management (PIM) or be subject to a time limit. It must be a direct, permanent assignment as a Global Administrator. Microsoft recommends a maximum of 4 Global Administrators per tenant. You must already factor in your two break-glass accounts here.<\/p>\n<p>&nbsp;<\/p>\n<h3>3. Group-based approach vs. individual accounts<\/h3>\n<p>Should break-glass accounts be organized into a security group? Opinions on this often differ. Here at TEAL, we have a clear stance on this:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>The single-account approach<\/strong><\/li>\n<li><strong>Our recommendation (group-based approach):<\/strong> Use a role-assignable security group. While this adds a layer of complexity, it allows you to enforce authentication methods such as passkeys (FIDO2) and device-bound profiles specifically for this group and restrict usage via AAGUIDs to approved hardware tokens (e.g., YubiKeys).<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][vc_empty_space height=&#8221;60&#8243;][vc_column_text css=&#8221;&#8221;]\n<h3>4. Restrict management via RMAU<\/h3>\n<p>Since accounts and groups are objects within the tenant, they could theoretically be manipulated or deleted by other privileged administrators. We prevent this by using <strong>Restricted Management Administrative Units (RMAU)<\/strong>. By placing your break-glass accounts and their security group within an RMAU, you completely block administrative access for standard administrators. Only explicitly defined identities can manage these accounts. A massive security gain.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Monitoring &amp; Procedures: When the emergency account whispers, the SOC must shout<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]An emergency account must <strong>never<\/strong> be used during normal operations. Every single login attempt, whether successful or failed, must immediately trigger a critical alarm with the highest priority.<\/p>\n<p>To achieve this, you must stream Microsoft Entra logs to a Log Analytics workspace (or directly to a SIEM such as Microsoft Sentinel). As soon as any activity is detected on the account, an automated alert must notify IT management and the Security Operations Center (SOC) via phone, SMS, or dedicated channels.<\/p>\n<p>Furthermore, even the best technical safeguards are useless without the appropriate organizational processes:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>Secure Storage:<\/strong> Passwords and hardware tokens should be stored in physical safes (e.g., at two separate company locations).<\/li>\n<li><strong>Regular testing:<\/strong> At least once a quarter, you must simulate an emergency scenario and thoroughly test the login process using the break-glass account.<\/li>\n<li><strong>Documentation &amp; training:<\/strong> Your IT staff must know instinctively where the keys are kept, who is authorized to open the safe, and what the technical steps for recovery entail.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text css=&#8221;&#8221;]\n<h2>Conclusion<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_column_text css=&#8221;&#8221;]A secure Microsoft Entra tenant isn\u2019t just defined by how well it fends off attacks, but above all by how resilient it is in the event of a disaster. A properly configured, group-based break-glass account protected via RMAU ensures that you can take action in an emergency instead of panicking.<\/p>\n<p>Have you already run through an emergency scenario for your tenant? We can help you elevate your IAM architecture to an enterprise level, avoid pitfalls during the Microsoft MFA migration, and make your emergency processes watertight.<\/p>\n<p>&nbsp;<\/p>\n<p><i><span style=\"font-size: 9pt;\">Source: <\/span><\/i><a href=\"https:\/\/www.google.com\/search?q=https:\/\/www.chanceofsecurity.com\/post\/break-glass-accounts-done-right-securing-emergency-access-in-microsoft-entra%23viewer-xk7cy32108\" target=\"_blank\" rel=\"noopener\"><i><span style=\"font-size: 9pt;\">Chance of Security<\/span><\/i><\/a>[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/6&#8243;][\/vc_column][vc_column width=&#8221;2\/3&#8243;][vc_empty_space height=&#8221;100&#8243;][vc_column_text css=&#8221;&#8221;]\n<h4 style=\"text-align: center;\">If you&#8217;d like to learn more about this blog post and discuss it with a TEAL expert, book a consultation here!<\/h4>\n[\/vc_column_text][vc_empty_space height=&#8221;50&#8243;][vc_raw_html css=&#8221;&#8221;]JTNDZGl2JTIwY2xhc3MlM0QlMjJmcmFtZSUyMiUzRSUwQSUyMCUwQSUyMCUzQ2ElMjBocmVmJTNEJTIyaHR0cHMlM0ElMkYlMkZvdXRsb29rLm9mZmljZTM2NS5jb20lMkZib29rJTJGQmVyYXR1bmdzZ2VzcHJjaCU0MHRlYWwtY29uc3VsdGluZy5kZSUyRiUyMiUyMHRhcmdldCUzRCUyMl9ibGFuayUyMiUzRSUzQ2J1dHRvbiUyMGNsYXNzJTNEJTIyY3VzdG9tLWJ0biUyMGJ0bi0zJTIyJTNFJTNDc3BhbiUzRUFwcG9pbnRtZW50JTIwJTNFJTNFJTNDJTJGc3BhbiUzRSUzQyUyRmJ1dHRvbiUzRSUzQyUyRmElM0UlMEElMjAlMjAlMEElM0MlMkZkaXYlM0U=[\/vc_raw_html][\/vc_column][vc_column width=&#8221;1\/6&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;100&#8243;][vc_raw_html css=&#8221;&#8221;]JTNDYSUyMGhyZWYlM0QlMjJqYXZhc2NyaXB0JTNBaGlzdG9yeS5iYWNrJTI4JTI5JTIyJTNFJTNDc3BhbiUyMHN0eWxlJTNEJTIyY29sb3IlM0ElMjAlMjNmZjIwNzAlM0IlMjIlM0UlM0MlM0MlMjBCYWNrJTNDJTJGc3BhbiUzRSUzQyUyRmElM0U=[\/vc_raw_html][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;50&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h4>LATEST POSTS<\/h4>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/06\/01\/microsoft-entra-break-glass-best-practices\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-1024x576.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-1536x864.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal-700x394.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/MS-Entra-Break-Glass-Teal.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/06\/01\/microsoft-entra-break-glass-best-practices\/\">Emergency Access in Microsoft Entra: Best Practices for Your Break-Glass Accounts<\/a><\/h4>\n                            <p class=\"excerpt\">The so-called \u201cbreak-glass\u201d accounts. In this article, we'll show you how to securely set up, harden, and monitor this last line of defense in Microsoft Entra according to current best practices....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 June, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/05\/03\/why-your-windows-hardening-will-be-outdated-in-march-2026\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/10\/teal-blog_system-hardening-headerbild.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/05\/03\/why-your-windows-hardening-will-be-outdated-in-march-2026\/\">Configuration Vulnerability? Why Your Windows Hardening Will Be Outdated in March 2026<\/a><\/h4>\n                            <p class=\"excerpt\">With the March 2026 update, the rules for Windows 11 and Windows Server have changed. It is essential that you familiarize yourself with these changes and adjust your hardening configuration....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">03 May, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\">BSI Update: Grundschutz++ Will Become Mandatory in 2028 \u2013 Why You Should Take Action Now<\/a><\/h4>\n                            <p class=\"excerpt\">The wait is over: The BSI has published the first guidelines for Grundschutz++. What at first glance looks like additional bureaucratic red tape is, in fact, the new \u201cstate of the art\u201d for NIS2. ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The so-called \u201cbreak-glass\u201d accounts. In this article, we&#8217;ll show you how to securely set up, harden, and monitor this last line of defense in Microsoft Entra according to current best practices.<\/p>\n","protected":false},"author":14,"featured_media":1007790,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1007793","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1007793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=1007793"}],"version-history":[{"count":2,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1007793\/revisions"}],"predecessor-version":[{"id":1007794,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1007793\/revisions\/1007794"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/1007790"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=1007793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=1007793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=1007793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}