Skip to main content

๐Ÿ“๐ŸŸขNLOC - Panic Room

In case of emergency, break glass. This is the one room the glass opens into: a locked-down location the emergency accounts may use, and nothing else may.

๐Ÿ“Type Named location (IP)๐ŸŸขTrust Trusted, restricted
reference-build ยท nloc-panic-roomGolden Master reference
License tier
Business Premium (Entra ID P1)
Control plane
Entra Named Locations
Definition
A small, owned IP range
Reversibility
clean-revert

What this location is about ๐Ÿšชโ€‹

Break-glass accounts are the keys of last resort: the highly-privileged, non-MFA emergency logins you use when everything else is on fire. Their strength is also their danger, so they need a cage. This Named Location is that cage: a small, tightly-controlled set of IPs that the break-glass accounts are permitted to sign in from, and the companion policy blocks them everywhere else.

The Ring goes in a locked drawer, and this is the drawer. One room, owned by you, from which the account that can do anything is the only account allowed in.

๐Ÿค” Small on purpose

This is the opposite of the Customer Locations list. That one is generous, the whole office. This one is deliberately tiny: the fewer IPs the emergency account can appear from, the smaller the world in which a stolen break-glass credential is usable at all.

Why this matters ๐Ÿ•ต๏ธโ€‹

A break-glass account is exempt from the MFA and session policies that protect everyone else, because it has to work when those very systems are down. That exemption is exactly what makes it a prize: crack it and you skip the whole baseline. Location is the control that remains when MFA has been set aside. Pin the account to a room you physically or administratively control, and a leaked password is close to useless from anywhere an attacker actually is.

It is the last line precisely because it does not depend on the identity layer. When MFA is the outage, geography is still standing, and this tiny trusted location is how the emergency door stays both usable by you and shut to everyone else.

๐Ÿ› ๏ธ Configurationโ€‹

Where: Entra admin center โ†’ Protection โ†’ Conditional Access โ†’ Named locations โ†’ IP ranges location.

  • Create an IP ranges location containing only the controlled egress you would actually recover from: the MSP's admin bastion, a jump host, a specific known office range. Keep it as small as it can be.
  • Mark it trusted, and treat it as more sensitive than any other trusted location.
  • Reference it from Block External Sign-in for Break-Glass Accounts, which blocks the break-glass accounts from every location except this one.
  • Document the recovery path: the whole point fails if, in a real emergency, nobody remembers which IPs count as the panic room.

Caveats โš ๏ธโ€‹

Test the door before you need it. A panic room you have never opened is a locked room. Periodically verify that a break-glass account can actually sign in from here, as part of break-glass testing, so the emergency path is proven and not theoretical.

Do not make it convenient. The temptation is to widen this to "wherever the admin happens to be". Resist it. Every extra IP is another place a stolen emergency credential works. Small and inconvenient is the design, not a flaw.

It protects the account, it is not the whole plan. Location-pinning is one control on the break-glass accounts, alongside a phishing-resistant method, tight monitoring, and alerting on every single use. This is a wall of the room, not the room.

License and reversibility. Named Locations are Entra ID P1, included in Business Premium. Clean-revert, and because this guards the keys of last resort, any change to it is the highest priority a drift-detection alert can have.


The account that can do anything should be reachable from almost nowhere. Build the smallest room you can live with, and keep the keys of last resort inside it. ๐Ÿšช