Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when a JIT access programme relies…
Governance, Ownership & Risk

What breaks when a JIT access programme relies on break-glass and shared admin credentials?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

The programme stops governing the access that matters. JIT can still produce clean request logs while real privileged work happens through emergency accounts, shared credentials, or persistent side paths. When that happens, the workflow becomes evidence of approval activity, not evidence of effective control over privileged execution.

When JIT Becomes Paperwork Instead of Privilege Control

JIT only changes security outcomes when the temporary grant is the path actually used for privileged work. If administrators can still complete tasks through break-glass accounts, shared admin logins, or other persistent credentials, the programme is managing approval flow rather than governing execution. The result is a control that looks disciplined on paper but leaves real privilege standing outside it.

That gap is why access path design matters as much as request approval. A JIT workflow can be fully logged, time-bounded, and ticketed, yet still fail to constrain the account or secret used to reach production if operators bypass the intended path.

In practice, JIT has to be paired with credential uniqueness, session control, and a clear rule for where emergency access belongs. NHIMG’s Privileged Access Management Guide is useful here because it treats JIT, vaulting, session management, and zero standing privilege as one operating model rather than separate features.

Why Break-Glass and Shared Admin Credentials Undermine the Control

Break-glass access is not inherently wrong, but it must remain exceptional, tightly monitored, and outside the normal operating path. Shared admin credentials are more damaging because they erase attribution and make it impossible to tell which human or system actually exercised privilege. When both are present, the JIT programme may approve access without actually controlling the high-impact actions that follow.

That failure usually shows up as a control-plane mismatch: the approval system says access was temporary, while the underlying credential or emergency account remains continuously usable. The same issue appears when multiple operators know the same password, when a saved session persists beyond the JIT window, or when an emergency account is treated as a routine admin path. NHIMG’s Break-Glass and Emergency Access Account Guide is the right companion for understanding how emergency access should be designed and monitored without becoming a parallel standing privilege.

When organisations want to remove standing privilege rather than document it, the access grant must be the only route to the privileged action, not just the route to a ticket. NHIMG’s Just-in-Time Access and Zero Standing Privilege Guide supports that distinction by focusing on temporary elevation, eligible roles, and the path to actual standing-privilege removal.

What Good Looks Like When JIT Is Actually Enforcing Privilege

Healthy JIT programmes make the privileged account, secret, and session all expire or become unusable when the request ends. The operator should not be able to fall back to a shared password, a long-lived break-glass account, or an old authenticated session to finish the same task. If those alternatives exist, they need explicit governance, not informal acceptance.

The best operational test is simple: can you show that the approved path was the one used for the sensitive action? If the answer depends on a separate emergency account or a shared admin login, the programme is not enforcing least privilege, even if it is generating strong audit records. That is why secret lifecycle discipline matters as much as request workflow. NHIMG’s Guide to NHI Rotation Challenges and Guide to the Secret Sprawl Challenge both reinforce the operational burden of long-lived credentials and uncontrolled secret distribution.

For the same reason, shared admin credentials should be treated as a design smell, not a convenience. The programme is working only when attribution, revocation, and scope are all visible at the individual grant level. Shared use breaks all three at once.

Risk and Threat Considerations

Shared admin credentials and break-glass paths create a privileged backdoor that can be abused by insiders, stolen by attackers, or left active long after the original need has passed. The immediate risk is not just overprivilege, but loss of attribution and loss of control over what access really existed at the moment of action.

Failure mechanism: The JIT request is approved, but the privileged task is executed through a standing emergency account or shared credential, so the control never touches the actual access path.

Impact: Organisations get misleading evidence of compliance, delayed detection of misuse, weaker incident reconstruction, and a larger blast radius when the alternate credential is exposed or reused.

External guidance on non-human and machine-adjacent privileged access consistently treats credential lifecycle and privilege boundaries as the core issue. The OWASP Non-Human Identity Top 10 is relevant because the same failure pattern appears whenever temporary access is undermined by secret leakage, overprivilege, or long-lived credentials. The OAuth 2.0 Authorization Framework is also relevant as a reminder that access should be scoped and auditable at the grant level, not improvised through shared secrets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while CIS Controls v8, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingBreak-glass and shared admin access can linger beyond intended use.
NHI-02 — Secret LeakageShared admin credentials and fallback secrets undermine JIT enforcement.
NHI-05 — Overprivileged NHIEmergency and shared admin credentials often bypass least-privilege intent.
Recommendation — Remove or expire emergency and shared privileged access when it is no longer required. Protect and rotate privileged secrets so they are not reusable outside the JIT path. Constrain privileged credentials to the minimum scope needed for the approved task.
CIS Controls v8CIS-5 — Account ManagementJIT failures often come from unmanaged shared or emergency admin accounts.
Recommendation — Inventory, restrict, and review privileged accounts and remove unnecessary shared access.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementShared admin credentials and long-lived emergency secrets are authenticator lifecycle problems.
AC-6 — Least PrivilegeJIT only works when alternate admin paths do not preserve standing privilege.
AU-2 — Event LoggingBreak-glass use needs separate, reviewable evidence beyond normal JIT requests.
Recommendation — Manage privileged authenticators so shared or persistent credentials do not outlive their intended use. Limit privileged execution to the minimum access needed for the approved action. Log emergency and privileged actions separately so alternate access paths are visible in review.
OWASP ASVSV8 — AuthorizationThe issue is whether the approved path actually controls privileged actions.
Recommendation — Verify that privileged functions are authorized through the intended access path, not shared credentials.
OWASP API Security Top 10API5 — Broken Function Level AuthorizationA JIT workflow can approve access while the underlying privileged function remains callable by another path.
Recommendation — Enforce function-level authorization so alternate credentials cannot invoke privileged operations.

Practitioner Guidance

What to verify: Verify that the privileged action is only possible through the JIT-issued path, and that break-glass access is technically and operationally separated from routine administration. If a shared credential can still perform the same production action, the JIT control is incomplete.

Decision rule: If emergency access is needed, treat it as an exception path with separate monitoring, explicit ownership, and rapid post-use review. Do not allow it to become the normal way to complete JIT-approved work.

What practitioners underestimate: Audit logs can look healthy while the control is failing. The most important question is not whether access was requested and approved, but whether the approved identity, secret, and session were the ones actually used for the privileged operation.

Practitioner takeaway: JIT is effective only when it governs the execution path, not just the approval record, so any shared or emergency credential that can still carry out privileged work must be treated as a control bypass.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org