Break-Glass Account Checklist

A break-glass account is one emergency admin identity that exists for exactly one day: the day nobody can get in. The only admin's phone died with the only authenticator on it. The only admin left and nobody can say why. The identity provider itself is having an outage. Ransomware is on the clock. On that day, a working emergency login is the difference between a five-minute recovery and a two-day vendor-support hostage negotiation. On every other day, that same account is the credential an attacker wants most — which is why this checklist is mostly about keeping it asleep.

1. The lockouts this account is for

2. Build it right on day one

3. Seal it — offline, outside the vault it may need to rescue

4. Keep it asleep: the hardening rules

5. The trigger list: what counts as the emergency

6. The runbook for using it

7. The fifteen-minute quarterly test

8. Locked out right now, with no break-glass account?