One wrong Conditional Access policy and your entire organization is locked out. No exceptions. Not some users — everyone, including you.
These are the five mistakes I see most often. Each one has locked out real users in real environments.
Mistake 1: No break-glass account
This is the one that causes the most damage. A break-glass account is a cloud-only Global Administrator account that is excluded from every single Conditional Access policy. Its only purpose: if a misconfigured policy locks out all admins, you can still get in and fix it.
Most environments don't have one until after the first lockout.







