Home › Forums › Azure › SC-300 Microsoft Identity and Access Administrator › Break glass global admin accounts › Reply To: Break glass global admin accounts
-
Hello avrohomdu,
Thank you for taking the time to share your feedback with us. We truly appreciate your insight and fully agree with your preferred solution.
After reviewing the scenario and the provided options, we recognize that the solutions offered in the question, including Option 1 (monitoring via Azure Monitor alerts) and the other options, do not adequately address the issue of ensuring TD-Recovery remains accessible during disruptions. These options fail to ensure that the account can still authenticate if the on-premises Active Directory is unreachable, which is the core concern of the question.
We fully agree with your suggested solution of creating a cloud-only account for TD-Recovery, along with configuring backup MFA methods. This approach would indeed ensure the account’s availability during disruptions, regardless of the state of the on-premises infrastructure.
As a result, we’ve flagged this question for review and will update it in our next content cycle to better reflect the correct solution and ensure that it aligns with both real-world best practices and exam expectations.
Thanks again for the insightful feedback! This will help us improve the quality of our materials. Feel free to reach out if you have any follow-up questions.
Regards,
Lois @ Tutorials Dojo