Step 0 — Break-glass accounts (before you touch anything)
A misconfigured policy can lock every admin out — including you. Break-glass accounts are the mat you land on. Confirm recovery and authentication dependencies before enforcement:
- Exclude emergency accounts from policies that could block or restrict emergency sign-in. Test independent phishing-resistant authentication. Microsoft mandatory administrative MFA requirements still apply.
Everything else about these accounts — creating them, credentials, monitoring, and optionally using restricted management after validating recovery and governance compatibility — is owned by the Privileged Access Dojo, so the guidance lives in exactly one place. Microsoft's reference: Manage emergency access accounts ↗
Size up your environment
A few questions. The dojo tailors the policy set to what you actually run — and tells you honestly when a policy isn't for you.
Do you manage devices with Intune?
Do external guests collaborate in your tenant?
What phones/tablets reach work email or Teams?
Does anyone manage Azure resources?
How far do you want to push passkeys / FIDO2?
Do you want to go passwordless?
What do staff work on?
Do you use Microsoft Entra agent identities?
Have you confirmed agent-risk licensing and preview availability?
Step 0.5 — Passwordless readiness
Passwordless isn't a Conditional Access setting. It's a registration project with a Conditional Access policy at the end of it. Enforce the policy before people hold the credential and you lock them out. Here's what has to be true first.
Walk out with a plan
Your plan reflects recorded answers and progress. The JSON bundle is an array of report-only Graph examples with placeholder IDs. Validate each policy individually against the documented API or supported portal format before import; bundle-array import compatibility has not been verified.