Forum Discussion

schiachris's avatar
schiachris
Occasional Reader
Apr 16, 2026

Excluding break-glass account from MFA Registration Campaign – impact on existing users?

Hi everyone,

 

I'm currently reviewing the configuration of a break-glass (emergency access) account in Microsoft Entra ID and I have a question regarding MFA registration enforcement.

 

We currently have an Authentication Methods Registration Campaign enabled for all users for quite some time. We identified that the break-glass account is being required to register MFA due to this configuration.

 

The account is already excluded from all Conditional Access policies that enforce MFA, so the behavior appears to be specifically coming from the registration campaign (Microsoft Authenticator requirement).

 

Our goal is to exclude this break-glass account from the MFA registration requirement, following Microsoft best practices.

 

My question is:

If we edit the existing registration campaign and add an exclusion (user or group), could this have any impact on users who are already registered?

Specifically, could it re-trigger the registration process or affect existing MFA configurations?

 

We want to avoid any unintended impact, considering this campaign has been in place for a long time.

 

Has anyone implemented a similar exclusion for break-glass accounts within an active registration campaign? Any insights or confirmation would be really helpful.

 

Thanks in advance!

No RepliesBe the first to reply