Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsA break-glass account is a highly privileged emergency account used to restore administration when normal administrator accounts or their sign-in methods are unavailable. Keep it out of routine work: create redundant accounts, protect them with strong authentication and controlled custody, and test and monitor them so they remain usable without becoming an easy route into your systems.
What is a break-glass account?
“Break-glass account” is a common name for an emergency access account: a privileged identity reserved for situations where normal administrative accounts cannot be used—for example, if administrators are locked out or the usual authentication path fails. Microsoft describes its intended use as “emergency or ‘break glass’ scenarios where normal administrative accounts can’t be used.” It is not a spare account for everyday administration.
The account must be usable during the failure it is meant to address. That creates a deliberate security trade-off: protect it strongly, but do not make its access depend on the same identity provider, device, or policy control whose failure could trigger an emergency.
What should a secure design include?
Redundant accounts that do not depend on one employee
For Microsoft Entra ID, Microsoft recommends at least two emergency access accounts. Make them independent of individual employees and, in Entra, cloud-only rather than dependent on a federated identity provider. Redundancy helps if one account or its authentication method is unavailable.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Microsoft’s Entra guidance also recommends permanent active Global Administrator assignments for these accounts. That is a platform-specific recommendation for exceptionally privileged emergency identities, not a general rule for every identity system. Keep the number of broad administrator accounts and users small, and use least privilege for routine administration. CISA’s cloud guidance also supports least privilege, consideration of separation of duties, emergency-only global administrator accounts, and coordinated access in federal cloud contexts.
Strong authentication that can survive the emergency
Microsoft recommends phishing-resistant authentication for Entra emergency accounts, naming FIDO2 security keys and certificate-based authentication. It also advises using an authentication method different from the one used by ordinary administrator accounts. Choose only a method supported by your identity platform and workable with your enrollment and recovery procedures.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
A security key is one part of the design, not a complete solution: confirm supported key types, enrollment, custody, and how an authorized responder can use a backup if the primary method is unavailable.
Conditional Access policies that preserve recovery
A policy can lock out an emergency account if it requires a control unavailable during an outage, such as a compliant device or a particular MFA method. Microsoft’s Entra guidance recommends excluding emergency accounts from policies that block or restrict their sign-in, while protecting them through phishing-resistant authentication and other appropriate safeguards.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
This is not a blanket instruction to turn off MFA. Review each policy’s actual effect on emergency sign-in, document the intended exception, and test the exact configuration. Microsoft’s recommendations apply to Entra; other identity platforms may have different recovery-account controls.
Shared, controlled custody
Store credentials and authentication materials in secure locations accessible to multiple authorized responders, with access controlled and auditable. Do not tie the account to an employee’s personal phone or device. Microsoft recommends keeping credentials in separate secure locations and using a designated secure workstation or Privileged Access Workstation when signing in.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Define who may retrieve the credentials, how that access is approved, and how responders will record their actions. The custody arrangement should remain available if one administrator or their usual device is unavailable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should you operate and test the accounts?
Monitor every use
Configure alerts for all sign-ins and relevant audit events involving emergency accounts. CISA recommends extensive administrative logging and auditing, along with detection of anomalous administrative activity. Protect the monitoring path so an incident affecting ordinary administration does not silently disable visibility into emergency-account use.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Every use should trigger investigation and documentation: identify who used the account, why ordinary access failed, what actions were taken, and what follow-up is required. Emergency use should not disappear into ordinary administrator activity.
Test sign-in readiness
Microsoft Learn recommends validating Entra emergency access accounts regularly—at least every 90 days is its stated recommendation, with quarterly testing given as an example. Test both accounts and repeat testing after material changes to authentication or Conditional Access. Record the outcome and confirm that the test does not leave credentials exposed or sessions active.
- Confirm the account, its assigned emergency role, and its authentication method are available to authorized responders.
- Use the designated secure workstation and verify that sign-in succeeds under the current policy configuration.
- Confirm that the expected sign-in and audit events generate alerts and can be reviewed.
- End the session, secure or rotate credentials if the procedure requires it, and record the test result and any remediation.
How do Microsoft Entra recommendations apply elsewhere?
The detailed recommendations above—cloud-only accounts, permanent active Global Administrator assignments, and exclusions from certain Conditional Access policies—are specific to Microsoft Entra guidance. Microsoft 365 admin security guidance separately recommends two emergency accounts and a 16-character password in the scenario where those accounts are excluded from MFA requirements; that password recommendation should not be generalized to other configurations or platforms.
If your organization uses another cloud identity provider, an on-premises directory, or a hybrid environment, apply the broader principles—independent recovery access, strong authentication, controlled custody, least privilege, monitoring, and regular tests—using that platform’s current official recovery guidance. Do not copy Entra role or policy settings without checking their equivalent and testing the resulting access path.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

