Skip to content

Second attempt to resolve doc bug microsoft support asked me to submit#1970

Open
jonwbstr wants to merge 4 commits into
MicrosoftDocs:mainfrom
jonwbstr:jwpatch-1
Open

Second attempt to resolve doc bug microsoft support asked me to submit#1970
jonwbstr wants to merge 4 commits into
MicrosoftDocs:mainfrom
jonwbstr:jwpatch-1

Conversation

@jonwbstr
Copy link
Copy Markdown

Hello,

My previous attempt to bring the documentation in align with what Microsoft support told me is correct was pull request #1708.
The request was closed without explanation. Please let me know the best way to incorporate the feedback received from Microsoft support into the public documentation.

If I should be going about this another way, I apologize for the misunderstanding and thank you in advance for point me in the right direction.

Regards,
-jon

According to ticket 2502260010001012 this article describes the workaround of using the break glass account to forward admin email notifications to admin accounts configured with PIM, or following Microsoft's guidance to have separate unlicensed global admin accounts and licensed mail-enabled users with no admin roles found in the following article

https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-protect-admin-accounts?view=o365-worldwide#create-a-user-account-for-yourself
@prmerger-automator
Copy link
Copy Markdown
Contributor

@jonwbstr : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod
Copy link
Copy Markdown
Contributor

Learn Build status updates of commit e47fd79:

✅ Validation status: passed

File Status Preview URL Details
docs/identity/role-based-access-control/security-emergency-access.md ✅Succeeded

For more details, please refer to the build report.

@v-regandowner
Copy link
Copy Markdown
Contributor

@rolyon

Can you review the proposed changes?

IMPORTANT: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error: Your billing is not configured or you have Copilot licenses from multiple standalone organizations or enterprises. To use premium requests, select a billing entity via the GitHub site, under Settings > Copilot > Features.

@jonwbstr
Copy link
Copy Markdown
Author

Currently microsoft documentation has a "feedback" button where people can contribute. In the past, the feedback was collected in github and the community could see the feedback and see what happened with it. I'm not sure how to locate the feedback submitted through the new system. I have shared feedback for years and the loss of transparency and challenges determining how that feedback has been incorporated into the documentation is leading me to try novel approaches to finding answers.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated 6 comments.

- Unforeseen circumstances such as a natural disaster emergency, during which a mobile phone or other networks might be unavailable.
- If role assignments for Global Administrator and Privileged Role Administrator roles are eligible, approval is required for activation, but no approvers are selected (or all approvers are removed from the directory). Active Global Administrators and Privileged Role Administrators are default approvers. But there will be no active Global Administrators and Privileged Role Administrators and administration of the tenant will effectively be locked, unless emergency access accounts are used.
- Global Administrators are using separate unlicensed admin accounts which do not receive Admin Email Notifications.
- Global Administrators are using Privilaged Identity Management (PIM) for **just-in-time** access to admininistrative roles such as Global Administrator and also need to receive Admin Email Notifications.

1. [Validate accounts regularly](#validate-accounts-regularly).

## Forward Admin Email Notifications
1. [Validate accounts regularly](#validate-accounts-regularly).

## Forward Admin Email Notifications
This workaround is only intended for customers using [PIM](/entra/id-governance/privileged-identity-management/pim-configure) and/or [separate administrator accounts](/microsoft-365/business-premium/m365bp-protect-admin-accounts#protect-admin-accounts)
Comment on lines +57 to +65
## Forward Admin Email Notifications
This workaround is only intended for customers using [PIM](/entra/id-governance/privileged-identity-management/pim-configure) and/or [separate administrator accounts](/microsoft-365/business-premium/m365bp-protect-admin-accounts#protect-admin-accounts)

1. Make the break-glass account a shared mailbox

1. Create a Distribution List and add the licensed user accounts of any administrators using PIM and/or separate administraor accounts.

1. Forward mail from the breakglass account to the distribution group created in the step above

Comment on lines +60 to +64
1. Make the break-glass account a shared mailbox

1. Create a Distribution List and add the licensed user accounts of any administrators using PIM and/or separate administraor accounts.

1. Forward mail from the breakglass account to the distribution group created in the step above
Comment on lines +61 to +63

1. Create a Distribution List and add the licensed user accounts of any administrators using PIM and/or separate administraor accounts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants