← All controls

19 Break-glass admin + offline backup codes

draft

A separate admin account, used only in an emergency, whose credential and printed single-use backup codes are held offline. Its username is an unguessable random string, and it lives in a dedicated OU kept out of any third-party SSO profile and exempted from all Context-Aware Access restrictions, so an IdP outage, a CAA lockout or a compromise cannot lock you out of your own tenant. Every sign-in to it is alerted on — an account that is never used has no legitimate login. It is the recovery path for every other control here that can lock you out.

Caveats

Setup steps

  1. open ↗
    Admin console screen — Directory > Users (create the break-glass account)

    https://admin.google.com/ac/users · captured 2026-07-15

    Directory › Users

    New user (random-string username) in a dedicated OU; Security > Authentication > SSO profile = None for that OU; no CAA access levels assigned to that OU (№14)

  2. Activity rule on login events for this account (Rules, or Reporting > Audit and investigation > Create activity rule); alerts surface in the Alert Center

  3. Directory > Users > select the user > Security > 2-step verification > Get backup verification codes; sealed envelope, tamper-evident, split custody

Ongoing maintenance

How to verify

  1. Sign in with the break-glass account using a stored backup code from a clean browser. Re-seal fresh codes afterwards.

  2. Confirm it holds super admin and is excluded from SSO (№22) and CAA (№14) enforcement.

    gam print admins | grep <breakglass-address>

draft v0.2.0 Recover policy #3 · #11 ↗