Break-Glass Account
A tightly controlled emergency account used only when normal access fails, with strong vaulting, monitoring, and alerting. Tested regularly so it works in a real incident.
Break-glass accounts fail in two directions. Untested, they do not work during the outage they exist for, usually because they depend on the SSO or MFA service that is down. Untested and unmonitored, they become a standing backdoor that nobody notices being used. The rule that survives audit is: excluded from conditional access, credentials split and vaulted, every use alerts immediately, and the whole path is exercised on a schedule.
See also: what is PAM, zero standing privileges, just-in-time access, PAM vendors
Related on Start with Identity
- GlossaryIAM
Identity and Access Management. Workforce identity for employees, contractors, and partners. Covers authentication, authorization, lifecycle, and audit. Distinc
- GlossaryLeast Privilege
The principle of granting an identity only the access it needs, for only as long as it needs it. Reduces blast radius when an account is compromised. Least priv
- GlossaryNon-Human Identity (NHI)
Any identity that is not a person: service accounts, API keys, OAuth tokens, certificates, workloads, and AI agents. NHIs now outnumber human identities in most
- Blog1Password buys Apono, moving from credential vault to access control plane
Reported at 250 to 300 million dollars, the deal gives 1Password just-in-time privileged access across AWS, Azure, GCP, Kubernetes, Snowflake, and Databricks, a
- CVEBeyondTrust PRA and Remote Support unauthenticated command injection
Privileged Remote Access and Remote Support accepted a malicious client request and ran OS commands as the site user. Unauthenticated. CVSS 9.8. CISA KEV. A PAM
- BlogPalo Alto Networks closes its 25 billion dollar CyberArk acquisition
The largest deal in security industry history closed on 11 February 2026. CyberArk shareholders took 45 dollars cash plus 2.2005 Palo Alto shares per ordinary s