Recovering access using the break-glass account

When external identity providers, such as SAML or Active Directory, fail and prevent user authentication, a tenant admin can log on using the break-glass account to correct configuration issues and restore access for all tenant users.

Log in with the break-glass account

  1. Open the Command Center login page.

  2. Enter the break-glass account username and the password that you saved during the account generation.

  3. Set up the authenticator app using the QR code shown on the screen.

    For subsequent logins, you can enter either the OTP shown in the authenticator app or the one received over the email. All tenant admins of the company will receive an OTP over the email.

  4. Click Login.

  5. Reset the password as prompted.

    Note

    The break-glass account requires a new password during every login. You must copy and securely save the new password for the next emergency use.

  6. Click Proceed.

Update your identity provider configuration

  1. From the Command Center navigation pane, go to Manage > Account > Security.

  2. Click the Identity servers tile.

  3. Open and configure the identity server/SAML that you want to fix.

    For example, upload a new keystore file, or update metadata for your identity provider or service provider.

  4. Test and save the changes.

Reset password for administrator accounts

  1. From the Command Center navigation pane, go to Manage > Account > Security.

  2. Click the Users tile.

  3. Click the administrator account.

  4. In the User summary section, click the Edit button edit button outline grey/gray pencil.

  5. To reset the password, in the Password box, enter a new password.

  6. To update the email address, in the Email box, enter the email address, and then click Save.

For detailed steps about how to configure your identity provider, see Identity Provider Use Cases.

×

Loading...