How to protect those accounts is no secret. Microsoft, Google and the national cyber security centres describe it. Even so, according to Microsoft only 41 percent of users had a second step at sign-in in 2024.
What the basics are
The basics have six parts. They belong together, because leaving one out weakens the rest.
A second step
A password alone is not enough. When you sign in, you also confirm with your phone, a key or a passkey that it is you.
A key or a passkey
It only works on the real website. A fake login page gets nothing from it.
Weak routes closed
Text messages and voice calls are switched off as a second step once something stronger is in place.
A second way in
At least two emergency accounts with their own keys, for when the regular administrator can no longer get in.
A copy of the vault
A second copy of the password vault that still works when the first one will not open.
Recovery codes apart
Recovery codes and spare keys on paper, kept somewhere other than the accounts they are meant to rescue.
Microsoft recommends at least two emergency accounts, with different sign-in methods from the regular administrators. Google asks for more than one super administrator, each held by a different person. The American CISA requires at least two super administrators for both environments.
Since late 2024, Microsoft has required a second step for its admin portals, emergency accounts included. An emergency route that rests on a password alone is therefore no longer an option there.
Text messages and the password
A key or a passkey only really protects you once the weak routes are closed. Leave text messages in place as a fallback, and an attacker will choose that route. CISA, Microsoft, Google and the national cyber security centres therefore advise against text messages as a second step. Microsoft itself stops sending sign-in codes by text message in 2027.
The password still counts too, because it remains the first step. NIST and the national cyber security centres largely agree on what that takes today.
- at least fifteen characters
- preferably a phrase of three or more random words that you can remember
- a different password for every service, kept in a password manager
- no forced mix of capitals, digits and symbols
- changed only when you suspect it has leaked, not on a fixed date
- and always a second step alongside it
What it costs in time
How much time it takes depends mainly on the number of people and on whether there is a playbook.
One administrator, first time
Anyone doing this alone and for the first time quickly spends several working days on it. Every choice and every surprise lands with the same person.
With a playbook
An IT provider with a standard setup does the same work in a fraction of that time. The playbook mainly provides decisions that have already been made.
Several administrators
In a larger organisation, administrators work on different parts at the same time. Most of the work then goes into bringing every employee and their devices along.
Per person, the small organisation spends the most time. It makes nearly the same decisions as an organisation of thirty people, but often one person makes them all.
What it costs in money
What it costs depends on where you start. A mandatory second step with an app usually costs nothing extra. Rules that decide who signs in and how often require a more expensive plan.
You buy keys once. You pay for licences every month, for every user.
Why it takes so much effort
When setting it up, most of the work goes into decisions. Where do the keys and the codes go? Who looks after the emergency account? What happens if that person falls ill or leaves? Anyone who has arranged nothing yet has to think hard about this. After that, those decisions are made. The extra steps at sign-in remain.
On top of that, every vendor does it differently. Each names a passkey differently, shows it in a different place and handles recovery in its own way. Researchers who studied passkeys in 2024 found the settings across browsers and operating systems "wildly inconsistent".
People find it annoying, awkward and tiring. Anyone who finds something a nuisance looks for a way around it. In 2025 NIST wrote that poor usability leads to workarounds that undermine security. In a 2025 field study, one in five employees was very satisfied with a password plus a code, against sixty to seventy percent with a physical key.
As long as it is voluntary, many people therefore do not take part. In 2025 Okta counted seventy percent of employees with a second step. When Okta made the second step mandatory for its customers' administrators, every administrator had one by August 2025.
People take the path of least resistance. So set a strict minimum, and enforce it.
The safety net has to stand apart from what it backs up
In an earlier article I wrote about the safety net that depends on the same component. With accounts this happens on a small scale, and each time it looks defensible.
Codes in the vault
The recovery codes are in the password vault they are meant to open, or next to the password. Whoever has the password vault then has both steps.
One phone for everything
The emergency account can only get in with the same phone as the regular admin account. Lose that phone, and both are locked.
Recovery mail in-house
The recovery email address sits in the company's own domain. If the domain goes, the recovery mail goes with it.
Two keys in one drawer
The spare key lies next to the first. A fire or a burglary takes both.
Microsoft recommends keeping the credentials of emergency accounts in fireproof safes in separate locations. AWS mentions a vault or safe, and two people who have to grant access together. Google mentions the place where you also keep your passport.
That could be a sealed envelope in a fireproof safe at the office. A second copy then goes into a bank safe deposit box, or to a trusted person outside the company.
You only know whether an emergency account works when someone signs in with it and records that it worked. An emergency account that nobody tests is an assumption. An emergency account that everyone has forgotten falls outside every check. At Microsoft itself, an attacker got in at the end of 2023 through an old test account without a second step.
Maintenance comes with it
Once it is in place, the maintenance begins. Microsoft asks for a test of the emergency accounts at least every ninety days, and again when someone leaves or changes role. CIS, which publishes widely used security controls, asks you to check at least every quarter whether all active accounts are still needed. Google, AWS and the UK NCSC stress monitoring every use of admin and emergency accounts.
People replace their phones, lose a key, join and leave. The maintenance is small, but it takes lasting discipline. It needs an owner, a fixed moment and a test whose outcome is recorded somewhere.
From open door to bank vault
I put the starting positions on a scale from zero to a hundred percent, from an open door to a bank vault. For each step you see what it delivers, and what it asks in money, time, effort and maintenance.
- 0%Open doorA password only, on an entry plan.ProtectionCostTimeEffortMaintenance
- 25%Lock on the doorA mandatory second step with an app, and recovery codes on paper. Usually costs nothing extra.ProtectionCostTimeEffortMaintenance
- 50%Key and spare keyKeys or passkeys for the administrators, emergency accounts, and text messages switched off. A small purchase, once.ProtectionCostTimeEffortMaintenance
- 75%Access rulesRules that decide who signs in and how, and a password manager for everyone. A licence per user per month.ProtectionCostTimeEffortMaintenance
- 100%Bank vaultKeys for everyone, admin rights only on request and for a limited time, everything demonstrable. The most expensive plan.ProtectionCostTimeEffortMaintenance
Indicative. The dots show proportions, not measurements. Time is the setting up, effort the daily work with it, maintenance what it keeps asking afterwards.
Most of the protection comes from the first, cheap steps. Above fifty percent you mainly pay for control and for being able to prove it.
What you get back
Your accounts are then much better protected. How much better depends on where you started.
Microsoft studied accounts that showed suspicious activity. With a second step the risk of takeover fell by 99.22 percent, and by 98.56 percent for accounts whose password had already leaked. In 2025 Microsoft wrote that a second step that cannot be phished blocks over 99 percent of identity-based attacks. CISA calls such a sign-in the gold standard.
Signing in also becomes simpler. You reach for your phone or key, enter a PIN or use your fingerprint or face, and have far fewer passwords to remember.
It does not close every door. A stolen session, an app with too many permissions and a persuasive call to the help desk each need their own measures.
Also decide how someone gets back in after losing their key. That route has to be as strict as the normal sign-in.
What I typically see
- there is one administrator with full rights, and nobody ever decided it should be so
- the emergency account exists, and nobody knows when someone last signed in with it
- two-step verification is on for everyone except the accounts that matter most
- the admin account has a key, and text messages are still there as a fallback
- an employee who left no longer has an account, and their phone is still registered as a recovery method on a shared account
- the IT provider holds the only key to the admin environment, and no contract mentions it
- the setup is half finished, because the changeover took more time than anyone had budgeted
- the question of who can still get in only comes up when the administrator is ill or has lost their phone, and then under time pressure
Each of these points is small. Together they decide whether anyone gets in on the day it is needed.
The questions this raises
- Which accounts give access to all the others?
- How many people can reach them today, and what happens if the only administrator is unavailable tomorrow?
- Does the emergency route share a person, a phone, a mailbox, a vault or a vendor with the normal route?
- Are text messages and voice calls still switched on as a fallback?
- Where are the recovery codes and the spare keys, and who can reach them?
- When did someone last use the emergency route, and what shows that it worked?
- How much time and budget have you set aside for the setup, and for the maintenance after it?
The core
The basics that protect your accounts take time and maintenance, and depending on where you start, also money and a different way of signing in. In return you get a safety net you can rely on, and accounts that are much better protected.
Enforce the minimum, and test the safety net.
