Knowledge hub

Break Glass Emergency Credential Access

Break-glass emergency credential access is a controlled process that allows authorized personnel to retrieve selected privileged credentials when the primary access management system is unavailable. It is designed for planned or unplanned disruptions, such as an online outage, network failure, or disaster recovery event, including situations in which a cybersecurity incident makes the primary platform unavailable. With appropriate authorization, administrators can use credentials offline to maintain or restore critical systems.

Organizations often depend on privileged accounts to perform critical work, yet securing and accessing those accounts can create friction during urgent situations. Organizations must balance access controls that protect sensitive systems with the need to respond quickly, as poorly managed emergency access can expose those systems to unnecessary risk. Bad actors also continue to evolve their tactics, making it essential to preserve access security when systems are offline without weakening authentication, authorization, encryption, or accountability requirements. An effective break-glass procedure provides carefully governed offline access while limiting who can retrieve credentials, when they can retrieve them, and how their activity is recorded.

A break-glass capability can provide synchronized credential information from an encrypted local cache when the primary privileged access platform is unavailable. This approach supports business continuity, disaster recovery, and account recovery during emergency situations while preserving important access controls. Emergency credentials should be limited to authorized personnel, protected with encryption, logged when accessed, and reviewed after use.

Imprivata Privileged Access Management (PAM) supports break-glass emergency credential access, providing organizations with a secure method for retrieving privileged credentials when the PAM platform is unavailable because of a planned or unplanned outage. Authorized personnel can then use credentials during an outage to maintain or recover critical systems, subject to established access controls. The capability also supports encryption and auditability during emergency operations.

You are currently browsing

Product availability varies by region. Would you like to choose a different region?

No thank you, I'd like to continue