Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Using a Break Glass Process to Provide Security for Privileged Accounts current page
Link copied

Using a Break Glass Process to Provide Security for Privileged Accounts

Feb 22, 2017
Author:
Derek Smith 2025
Derek A. Smith
Founder, National Cybersecurity Education Center
Blog banner default
Using a Break Glass Process to Provide Security for Privileged Accounts
Derek Smith 2025
Derek A. Smith
Founder, National Cybersecurity Education Center

What Does Break Glass Mean?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

In computing, “Break Glass” is the act of checking out a system account password to bypass normal access control procedures for a critical emergency. This provides the user immediate access to an account they may not normally be authorized to access. This method is generally used for highest-level system accounts such as root accounts for Unix or SYS/SA for a database. These accounts are highly privileged and break glass limits them by the password time duration, with the aim of controlling and reducing the account’s usage to only when necessary to complete a certain task.

  • Learn More About Break Glass Scenarios Here

When do you Use a Break Glass Process?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Break glass is a quick means for extending a person’s access rights in exceptional cases and should only be used when normal processes are insufficient (e.g., the helpdesk or system administrator is unavailable). Examples of situations when “break glass” emergency access might be necessary are account, authentication, and authorization problems. In many companies, some critical tasks exist which—in exceptional cases—must be performed by a person not usually permitted to perform these tasks. For example, a junior physician would be able to perform certain tasks of a senior physician in case of emergency.

The break glass solution is based on pre-staged emergency user accounts, managed and distributed in a way to make them quickly available without unreasonable administrative delay. The break glass accounts, and distribution procedures should be documented and tested as part of implementation and carefully managed to provide timely access when needed.

A best-practice would place the pre-staged emergency accounts under the responsibility of an individual, such as an Emergency Account Manager, who would be readily available during operating hours and who understands the sensitivity and priority of the emergency accounts. This person would distribute the accounts with a sign-out method requiring an acceptable form of identification to be provided by the requestor and recorded before the accounts are made available.

An Example of a Break Glass Process

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

A "Break Glass Process" would look something like this:

  1. A user performs a break glass check-out when they need immediate access to an account they are not authorized to manage.
  2. In the break glass check-out process, a notification message is sent to the Emergency Account Manager, informing them that a break glass check-out process occurred. However, they cannot approve or stop the process.
  3. The checked-out break glass account is recorded for audit purposes.

While the emergency account is being used, it must be carefully monitored and audited on a regular basis. Additionally, the system should alert the security administrator when an emergency account is activated. The administrator will make sure the account properly closes when done and a new account established.

How Should You Manage a Break Glass Account?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The best way to manage a break glass account is using a privileged access management (PAM) solution. PAM is all about locking “root” or “admin” credentials up in a hardened vault and tightly controlling access to them for increased security. Enterprise password management provides an extra layer of control over privileged administration and password policies, as well as detailed audit trails on privileged access. In addition to controlling the use, distribution, and change of the break glass passwords, PAM solutions can also broker sessions to systems or databases so the privileged user never even sees the passwords or credentials.

Using a break glass solution in your organization is a way to ensure your critical systems are accessible when you need them most.

  • Learn How BeyondTrust Protects Privileged Access
Password Safe Overview

Videos

Password Safe Overview

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Netflix Breach: Orange, Black, and Another Hack
    May 1, 2017 Netflix Breach: Orange, Black, and Another Hack
    Blog
    1m
  • Endpoint Privilege Management - Why Streamlined Workflows Mean Stronger Security
    Feb 14, 2024 Endpoint Privilege Management - Why Streamlined Workflows Mean Stronger Security
    Blog
    1m
Share this Article
  • Link
Tags
  • Access Control
  • Account Authorization
  • Break Glass Account
  • Break Glass Account Management
  • Break Glass Distribution
  • Break Glass Emergency
  • Break Glass Implementation
  • Break Glass Method
  • Break Glass Policy
  • Break Glass Procedure
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.