Skip to main content

๐Ÿ›ก๏ธ๐Ÿง‘โ€๐Ÿ’ผโ›“๏ธ๐Ÿ”“Group - Break the Glass solution

What this group is forโ€‹

This is a dynamic security group created to contain your last-resort admin account.
The one you hope to never use โ€” but also hope actually works when you need it.

It's used in combination with:

If you're in this group:

โœ… You are excluded from baseline CA policies
โœ… You can sign in from one named location
โŒ You are completely blocked everywhere else


๐Ÿ” Configuration Overviewโ€‹

SettingValue
Group name๐Ÿ›ก๏ธ๐Ÿง‘โ€๐Ÿ’ผโ›“๏ธ๐Ÿ”“Group - Break the Glass solution
Group descriptionEmergency access account group. Dynamic. Strictly monitored. Restricted to a known named location only.
Group typeSecurity
Membership typeDynamic
Dynamic rule(user.userPrincipalName -contains "gordon.freeman")

๐Ÿ“„ Membership Governanceโ€‹

This group is managed by rule, not by hand.

  • Accounts must be provisioned with a predictable UPN
  • Membership syncs automatically across tenants (via SuperVision)
  • Every environment should track this group and validate it regularly

This isn't just another admin group. This one gets you in when nothing else works.


๐Ÿง  Final Noteโ€‹

This group bypasses all protections โ€” intentionally.
But with that comes responsibility.

๐Ÿ•ธ๏ธ "With great exclusions come great consequences."

So:

  • Monitor this group
  • Document why it exists
  • Donโ€™t forget it exists

Because one day you might need it.
And if it doesn't work... well, let's not get terminated.