---
title: "Break-Glass Access — Identity Glossary | IDSync"
description: "Break-glass access is a pre-provisioned, heavily monitored emergency account used only when normal authentication paths fail — for example when the IdP…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Break-Glass Access",
          "item": "https://idsync.com/glossary/break-glass-access"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/break-glass-access",
      "name": "Break-Glass Access",
      "alternateName": [
        "emergency access",
        "break-glass account"
      ],
      "description": "Break-glass access is a pre-provisioned, heavily monitored emergency account used only when normal authentication paths fail — for example when the IdP itself is down or an admin is locked out during an incident.",
      "url": "https://idsync.com/glossary/break-glass-access",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How many break-glass accounts do I need?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "At minimum two per critical system, owned by different humans, stored in different physical locations."
          }
        },
        {
          "@type": "Question",
          "name": "Should break-glass accounts have MFA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes — but with a factor that doesn't depend on the failing system (hardware key stored offline, not a phone-based push tied to the broken IdP)."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Break-Glass Access 

Privileged Access

# Break-Glass Access

Break-glass access is a pre-provisioned, heavily monitored emergency account used only when normal authentication paths fail — for example when the IdP itself is down or an admin is locked out during an incident.

Last reviewed 3 months ago

Key points

-   Exempt from SSO and federation (so it works when the IdP is down)
-   Credentials split, sealed, and stored offline
-   Every use triggers SIEM alert and post-incident review
-   Required by SOC 2, ISO 27001, and FedRAMP audits
-   Typically two or more accounts per critical system

## What it is

Break-glass accounts are the _in case of fire, break glass_ of identity. They're local admin accounts on critical systems — IdP tenant, cloud master account, payment processor — that bypass SSO so they remain usable when the SSO provider itself is unavailable.

## How it works

Credentials are generated, written down or stored in a sealed envelope / offline password manager, and split between two trusted owners (Shamir-style or two-person rule). The accounts are exempt from SSO and Conditional Access. Every authentication triggers an alert in SIEM. After use, the credential is rotated and re-sealed.

## When buyers care

-   IdP outages (the 2022 Okta and 2023 Auth0 incidents)
-   Cloud root account recovery
-   Ransomware response where normal IAM is compromised
-   Audit requirements for documented emergency procedures

## Common misconceptions

-   **Break-glass is not a backup for sloppy access management.** It's an outage-resilience and recovery control.
-   **Don't store break-glass passwords in the same SSO-protected vault.** That defeats the purpose.

## FAQ

### How many break-glass accounts do I need?

At minimum two per critical system, owned by different humans, stored in different physical locations.

### Should break-glass accounts have MFA?

Yes — but with a factor that doesn't depend on the failing system (hardware key stored offline, not a phone-based push tied to the broken IdP).

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[pam](/directory/category/pam)

### Vendors to evaluate

[cyberark](/directory/cyberark)[beyondtrust](/directory/beyondtrust)[delinea](/directory/delinea)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the pam category.

[Explore tools](/directory/category/pam)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.