Skip to main content
Version: 2.1.0

MT.1005 - All Conditional Access policies are configured to exclude at least one emergency/break glass account or group.

Overview​

It is recommended to have at least one emergency/break glass account or account group excluded from all conditional access policies. This allows for emergency access to the tenant in case of a misconfiguration or other issues.

See Manage emergency access accounts in Microsoft Entra ID - Microsoft Learn

Test Metadata​

FieldValue
Test IDMT.1005
SeverityHigh
SuiteMaester
CategoryCA
PowerShell testTest-MtCaEmergencyAccessExists
TagsCA, Maester, MT.1005

Source​

  • Pester test: tests/Maester/Entra/Test-ConditionalAccessBaseline.Tests.ps1
  • PowerShell source: powershell/public/maester/entra/Test-MtCaEmergencyAccessExists.ps1