Break-Glass Account
A break-glass account is a special high-privilege account kept in reserve for emergencies, used only when normal administrator accounts cannot be accessed. Its purpose is to guarantee that someone can still get into critical systems if regular sign-in methods fail, such as when all administrators are locked out. Because these accounts are powerful and rarely used, they are typically protected and monitored carefully.
A break-glass (emergency access) account is a specially designated, high-privilege account reserved for critical scenarios where normal administrative access paths fail, such as a Conditional Access lockout or a situation in which all administrators are unable to sign in. In platforms like Microsoft Entra ID, these accounts are intended for emergency-only use and, per some guidance, may be assigned tenant-level ownership to ensure access persists even when the identity control plane is impaired. Because such accounts bypass normal access controls, they are typically subject to strict safeguards, restricted usage, and close monitoring; specific configuration and control practices may vary by provider and environment.
Why it matters
A break-glass account addresses a specific and serious failure mode in identity and access management: the scenario in which normal administrative access paths stop working. This can happen when a Conditional Access policy misconfiguration locks out administrators, or when all administrators are otherwise unable to sign in. Without a pre-provisioned emergency access account, an organization can find itself locked out of the very identity control plane it needs to fix the problem, turning a recoverable misstep into a prolonged outage.
The risk is amplified by the powerful nature of these accounts. Because a break-glass account is high-privilege and, in some guidance, may be assigned tenant-level ownership to ensure access persists even when the identity control plane is impaired, it represents both a critical safety mechanism and a high-value target. An account that bypasses normal access controls must be treated with corresponding care; otherwise the safeguard itself becomes a liability. This is why such accounts are typically subject to strict safeguards, restricted usage, and close monitoring rather than being left available for routine convenience.
For security leaders, the value of a break-glass account is not purely technical. It is a governance and business-continuity decision about who can regain control of critical systems during a worst-case identity failure, under what conditions, and with what oversight. Deciding to provision, protect, and monitor these accounts is an executive-level risk choice, and accountability for how they are governed remains with the client organization and its officers.
Who it's relevant to
Inside Break-Glass Account
Common questions
Answers to the questions practitioners most commonly ask about Break-Glass Account.