Skip to main content

Break the Glass (Emergency Access)

Break the Glass accounts are emergency administrators you create in User & Roles. They have the same permissions as Global Admin, use a password (minimum 30 characters, no MFA), and exist so you are not locked out when SSO or your identity provider fails. Normal users are passwordless (magic link or SSO only). You may create up to five Break the Glass accounts per organization (recommended 2–3).
Always keep at least one Break the Glass account when Enforce SSO is enabled. Otherwise an IdP outage can lock out your entire organization.

When to Use It

  • Your identity provider (IdP) is down or experiencing issues
  • You need to access NeuralTrust during an SSO misconfiguration
  • Emergency situations where SSO login is not working
  • IT administrators need guaranteed access for incident response

Organization membership

Treat Break the Glass as an emergency-only account, and assign it to exactly one organization. Normal (non–Break the Glass) multi-org users may see a magic link first so membership is not disclosed before the email is verified — that path does not apply to Break the Glass.

How It Works

  1. An Owner or Admin creates a Break the Glass account in Platform settings → User & Roles (password ≥ 30 characters).
  2. Break the Glass authenticates with password only — it does not use SSO or magic link (single- or multi-organization).
  3. When Enforce SSO is on, members on a verified email domain use the configured IdP. External-domain guests still use magic link (see SSO). The Break the Glass account still uses password.
  4. Maximum five Break the Glass accounts per organization (recommended: 2–3).
  5. All Break the Glass logins are recorded in Audit Logs.

Normal user vs Break the Glass


  • Keep 2–3 accounts (max 5 per organization) — not everyone.
  • Rotate BtG passwords periodically; store them in your secret manager.
  • Treat every BtG sign-in as an incident (audit alerts fire for organization admins).
  • Disable or remove BtG access when the emergency is over.

Creating a Break the Glass Account

  1. Log in to NeuralTrust as Owner or Admin.
  2. Open Platform settings → User & Roles.
  3. Invite a user or edit a member and apply the Break the glass role template (or mark the user as Break the Glass). The console provisions a long password (≥ 30 characters) — store it in your secret manager.
  4. Confirm the account belongs to only this organization when possible.
  5. Configure your Email Domain, then enable Enforce SSO when ready — see Microsoft Entra ID SSO or Generic OIDC SSO.

Validation Errors


Removing Break the Glass Access

  1. Go to User & Roles.
  2. Edit the user and remove the Break the Glass role (or delete the account).
  3. The user then follows normal passwordless sign-in (magic link or SSO).

Audit Logging

All break-glass activity is logged for compliance and security monitoring.

Viewing Break-Glass Events

  1. Open Audit Logs in the console (location is moving; look under Telemetry / Logs when available).
  2. Filter by Event Type: Login Success.
  3. Look for break-glass sign-in events in the description.

Security Best Practices


FAQ

Q: What happens if my IdP is down and I’m not a Break the Glass user? You won’t be able to log in until the IdP is restored. Configure Break the Glass accounts proactively before enabling Enforce SSO. Q: Can a Break the Glass account also use SSO or magic link? No. Break the Glass always signs in with password only — it skips SSO and magic link, including if the account belongs to several organizations. Q: What if a normal (non–Break the Glass) account belongs to several organizations? That user receives a magic link before any organizations are shown, then picks an organization (and may continue with that org’s IdP if SSO is enforced). Prefer a dedicated single-org Break the Glass account for emergencies. Q: Is there a way to know when Break the Glass was used? Yes. All Break the Glass logins appear in Audit Logs with a specific flag. Q: What if I have no Break the Glass account and SSO goes down? You would be locked out. Always keep at least one Break the Glass account when Enforce SSO is enabled. Q: Where do I create Break the Glass accounts? Platform settings → User & Roles. Q: Can Members be Break the Glass users? Yes — apply the Break the Glass role in User & Roles. Accounts without that role are passwordless.