A compost-authority tabletop showed both Global Administrators would be locked out if the sole MFA method vendor failed. What should the security engineer configure for Azure-management MFA enforcement?
Select an answer to reveal the explanation.
Short Explanation
Keep two sealed emergency keys—cloud-only break-glass accounts—outside the Azure-management MFA policy so you are not locked out of the building when the MFA vendor goes dark. Do not simply turn MFA off for every admin.
Full Explanation
Emergency access (break-glass) accounts should be cloud-only, highly protected, and excluded from restrictive Conditional Access policies that enforce MFA for Azure management, so administrators can still recover the tenant if primary MFA methods fail. Disabling MFA for all admins or removing emergency accounts increases outage risk.