Question
A tenant will require phishing-resistant authentication for all users and all resources. Its two emergency access accounts use separate recovery credentials because they must remain usable if the new method or policy is misconfigured. Which design best preserves both enforcement and recoverability?