Skip to main content

Establish the right break-glass emergency access for your situation

  • August 4, 2026
  • 0 replies
  • 51 views

Forum|alt.badge.img+3

Why is layering the right break-glass options important? 

Standing emergency accounts can be a huge risk, but maintaining resilience is essential. Consider the things that can impact your organization: you might need to do something as huge as recovering secrets after a weather catastrophe or something as precise as accessing critical secrets that were maintained by a single individual who left your business. Spend some time setting up the right methods for your organization and products. 

 

Options for establishing emergency access 

There are a lot of choices for how you establish resilience and break-glass access depending on where the emergency access might be required.  

 

Vault access 

Delinea’s Resilient Secrets capability allows you to replicate critical secrets data in read-only mode to a secondary instance for safekeeping. It also lets you create break-glass accounts on the replica. This second instance can be whatever makes the most sense for your organization (for example, cloud-to-cloud, cloud-to-on premises, etc).  

Unlimited Vault Access grants an admin chosen by your organization access to all secrets and folders without explicit permission (it requires dual control to keep that access in check). This capability provides a way in for singular cases like a user leaving your organization abruptly. 

More vault-level break-glass options include exported secrets, mobile caching, and PCS/Server Suite agent offline operation. Each method serves a slightly different purpose that may or may not be a fit for your team so choose the one(s) right for you. 

 

Platform access 

If you use the platform, you’ll need to layer in a break-glass method for platform identity. Follow the guidance in our Platform Security Best Practices documentation to set up a primary and secondary emergency CloudAdmin account protected by AAL3 authentication for emergency situations.  

 

Server and Endpoint emergency access 

Resilience at the endpoint level requires setting the right policy types. Delinea’s default global settings include “Windows local admin login” and “Windows local admin emergency access” which allow access in the event of various failures. 

We strongly recommend leaving that setting in place while establishing the right policies for your organization. We also strongly recommend designating a minimum of one user who can log in and elevate when a server can’t reach the Delinea platform.  

 

Best practices for emergency access

As is often the case when it comes to security, we recommend (and support via the above) using a multilayered approach to ensure a highly resilient and secure system. 

 

What break-glass methods do you find interesting? Are there others we haven’t mentioned here?