One wrong Conditional Access policy and your entire organization is locked out. No exceptions. Not some users — everyone, including you.

These are the five mistakes I see most often. Each one has locked out real users in real environments.

Mistake 1: No break-glass account

This is the one that causes the most damage. A break-glass account is a cloud-only Global Administrator account that is excluded from every single Conditional Access policy. Its only purpose: if a misconfigured policy locks out all admins, you can still get in and fix it.

Most environments don't have one until after the first lockout.