Break-glass account

A highly privileged emergency account kept sealed for use when normal administrative access has failed, with every use alerted, reviewed and followed by a credential change.

A break-glass account, also called an emergency access account, is a privileged account kept in reserve for the situation where normal administrative access is unavailable, for example because the identity provider or the multi-factor service has failed. The name alludes to the fire alarm behind glass: use is permitted, but meant to be visible.

The controls sit around its custody and its use. Its credential is commonly held in a password vault or split between custodians under dual control. Any use should raise an alert, be reviewed, and be followed by a credential change. It is commonly designed not to depend on the systems whose failure it covers, such as single sign-on. NIST SP 800-53 Rev. 5 draws a distinction worth keeping: emergency accounts created during a crisis should be removed or disabled automatically after a set period (AC-2(2)), while standing accounts of last resort stay available and are not given automatic removal dates. A break-glass account is commonly the second kind, and still belongs in access review.

Exam relevance: a scenario is likely to describe an outage that locks administrators out and ask how access should be restored safely. Candidates are expected to favour a sealed, monitored emergency account over shared standing administrator credentials, and to treat every use as an event that needs review.