Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What is the difference between break-glass access and…
Authentication, Authorisation & Trust

What is the difference between break-glass access and just-in-time access?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Authentication, Authorisation & Trust

Break-glass access is emergency elevation for exceptional situations, while just-in-time access is routine, task-scoped issuance for normal work. The first exists for urgent exceptions; the second is how organisations prevent standing privilege from becoming the default. Both need strict logging, but they solve different governance problems.

Why Break-Glass and JIT Solve Different Access Problems

Break-glass access is designed for exceptions, not routine operations. It is the emergency path you keep available when normal controls fail, an incident blocks standard approvals, or a critical system needs immediate intervention. JIT access, by contrast, is the control path for ordinary work: time-bound, task-scoped access that is issued only when needed and withdrawn quickly after use.

The difference is governance, not just duration. Break-glass assumes urgency and tolerates a temporary control bypass, but only under stronger monitoring and post-event review. JIT assumes planned work and tries to prevent standing privilege from existing in the first place. Both belong in a mature privilege model, but they answer different questions about who should have access, when, and for how long. Privileged Access Management Guide

In practice, organisations often confuse the two because both involve elevation. That confusion leads to bad design: a break-glass account used as a convenience path, or JIT configured so rigidly that it cannot support urgent operations. The right model keeps emergency access exceptional and auditable, while using JIT to make temporary privilege the default pattern for routine administration. Break-Glass and Emergency Access Account Guide Just-in-Time Access and Zero Standing Privilege Guide

How the Controls Differ in Day-to-Day Operations

JIT access is usually paired with approval workflows, role activation, and automatic expiry. The practitioner objective is to reduce the time window in which elevated permissions exist, which lowers exposure if credentials are stolen or a privileged action is misused. It is especially effective for repeatable admin tasks, cloud operations, and elevated support work where the access need is predictable but not constant. Cloud PAM and CIEM Guide

Break-glass access is different because it is meant to work when the normal path does not. That may include account lockout, identity provider outage, MFA failure, or a production incident where approvals cannot wait. The control depends less on frequent use and more on a trusted emergency path that is tightly protected, separately monitored, and tested before an incident forces its use. Break-Glass and Emergency Access Account Guide Privileged Session Management Guide

That is why JIT is usually measured by how well it removes standing privilege, while break-glass is measured by whether it is available, monitored, and actually usable in an emergency. One is a routine control against privilege accumulation. The other is a continuity control for exceptional access failure.

What Good Practice Looks Like for Governance and Audit

A well-run programme treats JIT as the standard elevation method and break-glass as a separately governed exception. The audit trail should show who approved access, what was granted, when it expired, and whether the session was recorded or reviewed. If the same account is used for both routine elevation and emergencies, the governance model is usually too weak to prove intent or enforce accountability. Service Account Security Guide Ultimate Guide to NHIs, Regulatory and Audit Perspectives

Good practice also means testing the emergency path before you need it. A break-glass account that has not been exercised, rotated, and verified is a latent failure mode, not a safety net. JIT, by contrast, should be validated by how consistently it prevents standing access while still letting work complete without unnecessary friction. PAM Buyer's Guide

Risk and Threat Considerations

Break-glass access becomes dangerous when it drifts from emergency-only use into a hidden backdoor for convenience. Because it often carries broad privilege, it is an attractive target for abuse if poorly monitored, and it can create a large blast radius if credentials are exposed or reused. JIT reduces that exposure, but only if expiry, approval, and session controls are enforced consistently.

Failure mechanism: emergency accounts, long-lived elevated credentials, or weakly governed privileged roles can be reused, shared, or stolen, turning a control intended for resilience into a persistent high-risk access path.

Impact: attackers or insiders can gain broad administrative reach, bypass normal approval gates, and leave fewer signs if session logging, rotation, and review are incomplete.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementJIT and break-glass both depend on credential issuance, expiry, and rotation.
AC-2 — Account ManagementBoth access models require separate handling of privileged accounts and temporary activation.
AU-2 — Event LoggingThe difference relies on auditable emergency use versus routine time-bound access.
Recommendation — Enforce credential lifecycle limits and rotate emergency access material after each use. Manage privileged accounts separately and time-limit elevated access. Log elevation events, approvals, and emergency account use for review.
ISO/IEC 27001:2022A.5.15 — Access controlThis question is fundamentally about controlling who gets access and when.
A.8.2 — Privileged access rightsBoth patterns govern privileged access assignment and temporary elevation.
Recommendation — Define access rules that distinguish routine JIT from emergency break-glass use. Restrict privileged rights and keep emergency elevation tightly governed.

Practitioner Guidance

What to prioritise: Use JIT for routine elevation wherever the task can be time-bound and scoped. Reserve break-glass for the narrow set of situations where standard access cannot be assumed to work.

What to verify: Confirm that emergency access is isolated from everyday admin workflows, that it has a distinct approval and monitoring model, and that it can be rotated and tested without depending on the very controls it is meant to bypass.

Common mistake: Treating break-glass as a convenience admin account. If teams can use it for normal work, the organisation has effectively reintroduced standing privilege through the back door.

Practitioner takeaway: JIT is the operating model for normal privilege, while break-glass is the exception path for failure conditions; the mature design is one where emergency access exists, but never becomes the default way to get work done.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org