Break-glass account
Also known as Emergency access account
A highly privileged account excluded from conditional access, kept for emergencies when normal administrative access fails.
If a conditional access policy is misconfigured, or your MFA provider has an outage, every administrator can be locked out of the tenant at once. Break-glass accounts exist so there is always a way back in.
They need a long random password stored offline, cloud-only identity with no federation dependency, exclusion from all policies, and alerting whenever one is used. An emergency account nobody monitors is an unmonitored global administrator.
Where this comes up
Break-glass account sits inside our identity and access work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.