16 of 29 in All Controls
aws

Enforce Break Glass Access Procedures

IDAWS-IAM-008
Severity
critical
Automation
Auto
Category
iam
Enforcementmandatory
Complexity / Impact
low(none impact)
Cloud Scopeaws:account
Environments
production
Target Resources
iam_usercloudwatch_alarmsns_topic
Services
iamcloudwatchsnsorganizations
Tags
iamincident-responsebreak-glassemergency-accesslanding-zone
Frameworks
NIST 800-53ISO 27001PCI DSSSOC 2
Governance
Cloud Security (quarterly)
Audit Dates
2026-05-03 • 2026-06-06

Specification & Description

Establish a documented, auditable break-glass access procedure for emergency access to the Management account when IAM Identity Center or the corporate IdP is unavailable.

Technical Specifications

Break-glass access is the emergency fallback when normal federated access via IAM Identity Center fails - typically due to an IdP outage, Identity Center service disruption, or misconfiguration that locks out all federated users. The pattern consists of a single dedicated IAM user in the Management account with AdministratorAccess, hardware MFA enforced via an IAM policy condition, credentials stored in a physical safe or a highly restricted Secrets Manager secret in a separate security account, and an immediate CloudWatch alarm triggered on any sign-in or API call by this user. The user has no access keys and no console access without MFA - the MFA device is the physical control that governs who can use the account. Usage is a declared incident: the security team is paged, all actions are recorded in CloudTrail, and the session is terminated as soon as normal access is restored. An SCP prevents deletion of the break-glass user from any account other than the Management account. Member accounts do not have their own break-glass users - emergency access to member accounts is obtained by assuming a role from the Management account break-glass session.

Security Rationale

IAM Identity Center is a dependency for all human access in a well-configured landing zone. A single point of failure in the IdP or Identity Center configuration can lock out the entire operations team from the Management account during an active incident - precisely when access is most critical. A carefully controlled break-glass user with hardware MFA provides an out-of-band access path that does not depend on any federated identity infrastructure while remaining auditable and difficult to misuse.

Policy Exceptions (2)

The break-glass user is the only permitted IAM user with console access in the Management account. It is the explicit exception to the IAM user prohibition in AWS-IAM-004. It must be the only entry in any audit finding for active IAM login profiles in this account.

During an active declared incident, break-glass usage is expected and alarm notifications should be acknowledged by the on-call security lead rather than escalated as an unauthorized access event. A declared incident must be opened in the incident management system before break-glass credentials are retrieved from the safe.

Operational & Implementation Notes

Hardware MFA is mandatory for break-glass users - virtual MFA (authenticator app) stored on a personal device is not acceptable because device loss or compromise removes the physical control. Use a FIDO2 hardware key (YubiKey, Titan) or a dedicated TOTP hardware token stored with the credentials. The break-glass user should have no console password set in its normal state - the password is created as part of the activation procedure and deleted immediately after the session ends. This limits the window of exposure to the duration of the declared incident. Member account emergency access is handled by assuming an emergency role from the Management account session, not by creating break-glass users in every account. The CloudTrail log group name required by the Terraform alarm block must match the log group created by your CloudTrail configuration - typically /aws/cloudtrail or a custom name set in your landing zone baseline.

We value your privacy

We use analytics cookies to understand how visitors interact with our site and to improve the user experience. You can choose to accept or decline these cookies.