Skip to main content
Category: Identity & Access Management

Break-Glass Account

Also known as: Emergency Access Account, Emergency Account, Break Glass Account
Simply put

A break-glass account is a special high-privilege account kept in reserve for emergencies, used only when normal administrator accounts cannot be accessed. Its purpose is to guarantee that someone can still get into critical systems if regular sign-in methods fail, such as when all administrators are locked out. Because these accounts are powerful and rarely used, they are typically protected and monitored carefully.

Formal definition

A break-glass (emergency access) account is a specially designated, high-privilege account reserved for critical scenarios where normal administrative access paths fail, such as a Conditional Access lockout or a situation in which all administrators are unable to sign in. In platforms like Microsoft Entra ID, these accounts are intended for emergency-only use and, per some guidance, may be assigned tenant-level ownership to ensure access persists even when the identity control plane is impaired. Because such accounts bypass normal access controls, they are typically subject to strict safeguards, restricted usage, and close monitoring; specific configuration and control practices may vary by provider and environment.

Why it matters

A break-glass account addresses a specific and serious failure mode in identity and access management: the scenario in which normal administrative access paths stop working. This can happen when a Conditional Access policy misconfiguration locks out administrators, or when all administrators are otherwise unable to sign in. Without a pre-provisioned emergency access account, an organization can find itself locked out of the very identity control plane it needs to fix the problem, turning a recoverable misstep into a prolonged outage.

The risk is amplified by the powerful nature of these accounts. Because a break-glass account is high-privilege and, in some guidance, may be assigned tenant-level ownership to ensure access persists even when the identity control plane is impaired, it represents both a critical safety mechanism and a high-value target. An account that bypasses normal access controls must be treated with corresponding care; otherwise the safeguard itself becomes a liability. This is why such accounts are typically subject to strict safeguards, restricted usage, and close monitoring rather than being left available for routine convenience.

For security leaders, the value of a break-glass account is not purely technical. It is a governance and business-continuity decision about who can regain control of critical systems during a worst-case identity failure, under what conditions, and with what oversight. Deciding to provision, protect, and monitor these accounts is an executive-level risk choice, and accountability for how they are governed remains with the client organization and its officers.

Who it's relevant to

Virtual and Fractional CISOs
Security leaders advising client organizations often help determine whether break-glass accounts are provisioned, how they are governed, and how their use is monitored. This falls within the strategy, governance, and risk-management scope typical of a virtual or fractional CISO engagement, who advises and directs on these controls. Note that accountability for the accounts and the decisions around them typically remains with the client organization and its officers, and hands-on configuration may be out of scope unless explicitly contracted.
Identity and Access Management Teams
IAM administrators are typically responsible for creating, protecting, and monitoring emergency access accounts in platforms such as Microsoft Entra ID. They handle the practical safeguards, restricted usage, and monitoring that these high-privilege accounts require, and they are often the parties who would actually invoke a break-glass account during a Conditional Access lockout or a scenario where all administrators are unable to sign in.
IT and Cloud Operations Leaders
Those responsible for business continuity and platform availability rely on break-glass accounts as a recovery mechanism when normal administrative access fails. For them, the account is part of ensuring that someone can still regain control of critical systems when regular sign-in methods are unavailable, reducing the risk that an identity misconfiguration becomes a prolonged outage.
Organizations Adopting Cloud Identity Platforms
Businesses standing up or maturing environments like Microsoft Entra ID need to consider emergency access early, since the value of a break-glass account depends on it being provisioned before an incident occurs. The appropriate approach may vary by provider and environment, and its effectiveness depends on organizational maturity, defined scope, and disciplined protection and monitoring practices.

Inside Break-Glass Account

Emergency Access Account
A break-glass account is a highly privileged, standing account reserved for emergency use when normal authentication or access paths fail, such as during an identity provider outage, a locked-out administrator scenario, or a security incident that disrupts routine access controls.
Elevated or Administrative Privileges
These accounts typically carry broad administrative rights, often global or root-level, so that a designated responder can restore access or take critical action when standard delegated permissions are unavailable. Because of this power, the account represents concentrated risk if misused or compromised.
Credential Safeguarding and Custody
The credentials are commonly stored under strict controls, such as a sealed physical safe, a hardened password vault, or split-knowledge arrangements where no single person holds full access. Custody procedures define who can retrieve the credentials and under what conditions.
Usage and Activation Procedures
A documented process typically governs when the account may be invoked, who authorizes activation, and what steps follow use, including credential rotation after each use. This process is a governance control rather than a hands-on operational task.
Monitoring and Audit Logging
Break-glass accounts are usually configured for heightened monitoring so that any authentication or activity generates alerts and an auditable record, allowing the organization to review whether use was legitimate and appropriate.
Governance and Accountability Ownership
Responsibility for the design, policy, and review of break-glass accounts generally sits with the organization and its officers. A virtual or fractional CISO may advise on the policy, review the design, and direct improvements, but accountability for the control remains with the client organization.

Common questions

Answers to the questions practitioners most commonly ask about Break-Glass Account.

Is a break-glass account the same as a shared administrator account that the team uses for convenience?
No, and an expert would insist on correcting this conflation. A break-glass account is an emergency-access credential reserved for exceptional situations, such as when normal authentication systems or privileged access pathways fail. It is not intended for routine or convenient administrative work. Treating it as a general-purpose shared admin account undermines its control value, because the account should remain dormant, tightly restricted, and continuously monitored so that any use is a clear signal of an emergency rather than ordinary activity. A virtual CISO advising on this control typically emphasizes that day-to-day administration should occur through standard, individually attributed privileged accounts, not the break-glass credential.
Does having a break-glass account mean the organization is protected or compliant on its own?
Not by itself. A break-glass account is one control within a broader identity and access management and privileged access strategy; its existence does not guarantee compliance or prevent incidents. Its effectiveness depends on how it is governed, monitored, and tested. Frameworks and standards that address access control and privileged access, such as NIST CSF, ISO 27001, and SOC 2, generally expect emergency access to be documented, restricted, and auditable rather than simply present. A virtual CISO typically supports readiness by advising on policy, monitoring, and review, but accountability for implementing and maintaining the control usually remains with the client organization and its officers.
When advising on a break-glass account, what controls does a virtual CISO typically recommend around its storage and access?
In many engagements, a virtual CISO recommends that break-glass credentials be stored securely, such as in a vault or a sealed and controlled location, with strict limits on who can retrieve them. Recommendations often include separating knowledge of the credential (for example, splitting the password or requiring more than one person to access it), restricting the number of authorized individuals, and ensuring the account is excluded from routine access workflows. The specific controls may vary by provider and by the organization's maturity and existing tooling. The virtual CISO advises and directs on these controls, but hands-on configuration is generally out of scope unless explicitly contracted.
How is use of a break-glass account typically monitored and audited?
A virtual CISO often recommends that any use of the account trigger immediate alerting to appropriate stakeholders, and that all activity be logged and reviewed after the fact. Because the account should normally be dormant, any authentication or activity is typically treated as a high-priority event warranting investigation. Recommendations may include tamper-evident logging, review of what actions were taken during the emergency, and reconciliation against the reason the account was invoked. The value of this monitoring depends on the organization having functioning logging, alerting, and review processes in place, which is why maturity and client cooperation matter.
How often should a break-glass account and its procedures be tested?
A virtual CISO typically advises periodic testing to confirm that the account works when needed, that authorized personnel know how to invoke it, and that alerting and logging function as expected. The frequency may vary by organization and risk profile. Testing often includes rotating or resetting the credential after each use or test, verifying that access controls remain intact, and updating documentation. Without testing, an organization may discover during an actual emergency that the credential is stale, misconfigured, or unusable, which defeats the control's purpose.
Who is accountable for governing the break-glass account after a virtual CISO helps establish it?
Accountability for the account and the decisions surrounding its use generally remains with the client organization and its officers, even when a virtual CISO helps design the policy and controls. The virtual CISO advises, directs, and may help define ownership, review cadence, and escalation paths, but does not typically assume legal or organizational accountability unless a contract specifies otherwise. Because a virtual CISO engagement is usually part-time and remote, ongoing governance, such as approving access, reviewing logs, and enforcing rotation, typically depends on designated internal owners and their cooperation with the advised process.

Common misconceptions

A break-glass account is just a normal admin account kept as a backup.
It is a deliberately governed emergency control with restricted custody, activation procedures, and enhanced monitoring. Treating it as a routine backup admin account undermines the safeguards that make it defensible and often introduces standing risk rather than reducing it.
A virtual CISO who recommends break-glass accounts becomes accountable for their use or misuse.
A vCISO typically advises on and directs the policy and design, but legal and organizational accountability for the control and for actions taken with the account generally remains with the client organization and its officers unless a contract specifies otherwise. A vCISO also does not usually perform the hands-on administration or activation of these accounts.
Having a break-glass account guarantees continuous access and prevents lockout or breach.
It is a contingency mechanism, not a guarantee of availability or a preventive control against breaches. Its value depends on disciplined custody, tested procedures, and organizational maturity. A poorly governed break-glass account can itself become an attack path.

Best practices

Store break-glass credentials under strict custody controls, such as a sealed vault or split-knowledge arrangement, so that no single individual can unilaterally access and use the account.
Define a documented activation procedure specifying who may authorize use, under what emergency conditions, and what actions follow, and treat this as a governance control owned by the organization.
Enable heightened monitoring and audit logging so that any authentication or activity on the account triggers alerts and produces a reviewable record.
Rotate the credentials after each use and on a scheduled basis, and verify the account remains functional through periodic testing rather than assuming it will work during a real emergency.
Keep accountability with the organization and its officers, using a vCISO or fractional CISO to advise on and review the policy and design rather than to assume liability or perform hands-on administration.
Periodically review the account against relevant governance frameworks such as NIST CSF or ISO 27001, recognizing that such reviews support control maturity and readiness rather than guaranteeing compliance or certification.