Enterprise Identity & Access Management Platform  ·  View 26 of 27  ·  Assurance

Break-Glass & Identity Recovery

The path that exists precisely because every other path has failed.

Editable source SVG draw.io All views
Detect
Detect
Tenant lockout
CA misconfiguration
Tenant lockout...
Federation outage
external IdP down
Federation outage...
Admin compromise
hostile sessions active
Admin compromise...
Severity call
SecOps duty manager
Severity call...
Authorise use
Authorise use
Two-person rule
holder + witness
Two-person rule...
Credential retrieval
sealed, offline, split
Credential retrieval...
P1 alert fires
on sign-in, no exception
P1 alert fires...
Recover
Recover
Break-glass sign-in
FIDO2 hardware key
Break-glass sign-in...
Re-apply configuration
from the IaC repository
Re-apply configuration...
Revoke hostile sessions
and reset credentials
Revoke hostile sessions...
Microsoft escalation
if break-glass also fails
Microsoft escalation...
Verify
Verify
Normal access restored
sample sign-in per persona
Normal access restored...
Root cause captured
Root cause captured
Evidence pack
every action, timestamped
Evidence pack...
Reset
Reset
Rotate credential
within 24 hours
Rotate credential...
Re-seal and witness
Re-seal and witness
Post-incident review
outcome is a policy change
Post-incident review...
authentication fails
authentication fails
still broken, iterate
still broken, iterate
quarterly rehearsal
quarterly rehearsal
Break-Glass & Identity Recovery
Break-Glass & Identity Recovery
Risk / gap
Risk / gap
Decision point
Decision point
Security / platform
Security / platform
Interface / broker
Interface / broker
Data store
Data store
failure / alternate
failure / alternate
event / async
event / async
Break-glass is tested, not trusted. The quarterly rehearsal drives the loop back to the first stage on purpose: a credential nobody has signed in with for a year is an assumption, and RTO for tenant-level recovery is 4 hours only because it has been measured.
Break-glass is tested, not trusted. The quarterly rehearsal drives the loop back to the first stage on purpose: a credential nobody has signed in with for a year is an assumption, and RTO for tenant-level recovery is 4 hours only because it has been measured.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

Decisions

  • Two accounts, not one and not six. One is a single point of failure during an incident; six is a standing privilege problem.
  • Credentials are split and sealed offline, retrieved under a two-person rule with a witness. The control is procedural, and that is stated rather than dressed up as technical.
  • Every break-glass sign-in raises a P1 alert with no exception path. An emergency account nobody notices being used is an attacker's account.

Tested, not trusted

  • Quarterly rehearsal: sign in, confirm the account still works, confirm the alert fires, re-seal. RTO for tenant-level recovery is 4 hours because it has been measured, not estimated.
  • Recovery re-applies configuration from the IaC repository rather than reconstructing it by hand, which is the main reason view 21 exists.
  • The Managed HSM security domain is held under the same custody procedure. Losing it is unrecoverable, so it is part of the same rehearsal.

Risks

  • These accounts are excluded from all Conditional Access policies except one requiring a FIDO2 hardware key, so a stolen hardware key plus vault access is the whole attack.
  • If break-glass itself fails, the only remaining path is Microsoft support escalation, which is measured in hours and is outside our control.
  • The rehearsal is the control that decays first. It is a calendared, owned commitment; a missed quarter is a reportable risk, not an administrative slip.