Preparing continuity
Two prerequisites decide whether continuity helps anyone in an emergency: an account for everyone who is to read, and a sign-in path that works without email.
Continuity can run technically flawlessly and still help nobody. Two prerequisites have to be met before the outage, and neither can be created afterwards. Both have the same reason: the way to catch up on them runs through email, and email is exactly what is not working.
The continuity overview page shows how far the tenant has got on both points and names the addresses where something is still missing.
First prerequisite: an account for everyone who is to read
The continuity view shows everyone exactly the messages that went to their own addresses. For that the person has to be known as a member of the tenant.
A customer with eighty mailboxes and two administrator accounts has seventy-eight people without access during an outage. Sending invitations afterwards no longer helps, because an invitation is an email and would go to exactly the mailbox that is down.
The invitation is issued from the continuity view, for all addresses from the directory at once. It is advisable to do that right at setup and not only when the view is needed.
Second prerequisite: a sign-in path without email
Anyone who signs in exclusively through Microsoft cannot get in during an outage of Entra ID, and an Entra outage is the most common case of all. A sign-in link by mail helps just as little, because it would go to the failed mailbox.
Two paths remain that hold independently:
- A password that has been set. The simplest way, available for every account and set up in seconds.
- A passkey. More convenient day to day, but it requires a device that is at hand in an emergency.
On an in-house installation the password is the only path offered anyway.
The overview page lists which members still have no outage-proof sign-in path. The reminder about it goes out as an email, as long as that is still possible.
Third recommendation: a contact address outside
The outage notification goes to everyone who may configure continuity. Their mailboxes as a rule sit in the same domain that has just failed, and then the notification lands in the continuity store, which you only find if you already know it exists.
That is why an emergency contact address can be stored. An address outside your own domains makes sense, for instance that of the service provider or a private address of the responsible person. When sending the notification, Conbool always prefers the addresses that are reachable at that moment.
If there is not a single reachable address, that is recorded explicitly instead of sending a notification and claiming success.
A drill does no harm
Continuity can be switched on by hand for a maintenance window, without anything having failed. That is the simplest way to find out whether sign-in holds and whether the right people see the view. It is described under settings.