Emergency Access Account
An emergency access account is a special, highly privileged account kept in reserve so administrators can regain control of an identity system when normal access fails, such as during a lockout or major outage. It is used only in rare, critical situations rather than for day-to-day work. Organizations are typically advised to maintain more than one such account to avoid a single point of failure.
An emergency access account (also called a break-glass account) is a highly privileged account provisioned in advance to preserve administrative access to an identity environment when standard authentication or authorization paths are unavailable, such as inadvertent lockout, federation failure, or loss of other admin credentials. In Microsoft Entra ID deployments, these accounts are commonly assigned the Global Administrator role so that operators can regain control of the tenant during an emergency. Microsoft's guidance recommends maintaining multiple emergency access accounts to reduce the risk of a single point of failure; exact configuration, credential handling, and monitoring controls vary by deployment and are out of scope for this definition. Note that such accounts pertain to privileged access recovery and should be governed under strict access controls and monitoring, though the specific safeguards depend on organizational policy.
Why it matters
Identity systems concentrate enormous operational risk: if the normal authentication or authorization paths fail, administrators can lose the ability to manage the very system that controls all other access. A misconfigured Conditional Access policy, a federation outage, an expired credential, or the accidental removal of the last privileged administrator can leave a tenant effectively ungoverned at precisely the moment control is most needed. Emergency access accounts, commonly called break-glass accounts, exist to preserve a recovery path when those standard paths are unavailable.
Because these accounts hold extraordinary privilege, in Microsoft Entra ID deployments they are commonly assigned the Global Administrator role, they are also an attractive target and a significant liability if left unmonitored. The same properties that make them valuable during an outage (broad authority, independence from normal sign-in dependencies) make them dangerous if compromised or misused. This tension is why Microsoft's guidance treats them as accounts to be provisioned deliberately, governed under strict controls, and reserved for rare, critical situations rather than day-to-day administration.
Who it's relevant to
Inside Emergency Access Account
Common questions
Answers to the questions practitioners most commonly ask about Emergency Access Account.
