π¦π΄π¨βπΌCA - Block External login for BTG
What this policy is forβ
This Conditional Access policy is built to block everything for Break-the-Glass (BTG) accounts β except from one safe place.
Itβs not about convenience. Itβs about control.
Even if credentials are compromised, theyβre useless outside your trusted perimeter.
Used in combination with:
π Configuration Overviewβ
π Purpose and Impactβ
This policy creates a sealed environment:
Access is fully blocked unless the login originates from the exact named location.
It's the cleanest way to ensure:
- BTG credentials are useless in the wrong place
- No need to maintain exclusions in every new policy
- SuperVision-based setups stay clean and repeatable
π§ Governance & Securityβ
Break-the-Glass accounts should be rare, isolated, and restricted:
- Only your lead security team should know of this account
- Donβt store credentials in your regular password vault
- Use a separate protected vault (with access audit logging)
- Log and alert on any sign-in, successful or failed
- Regularly validate the named location and account state
π βIf everyone knows where the key is hidden, itβs not a secure door.β
π§ Final Noteβ
This isnβt just another policy β itβs your digital airlock.
Set it.
Test it.
Forget itβ¦ until the day youβll be glad itβs there.
π΅οΈ βIf your BTG login works from Starbucks, itβs not a BTG account β itβs a liability.β