Break Glass solution for giving a client emergency access to domain admin account document

Hi all

Does anyone use or have recommendations for a Break Glass secure emergency access document store.
I have a client who wants to be able to access a “break glass document” in the case of an emergency where they are unable to contact us.
I would like the solution to email me when the document is accessed so I know if the details have need accessed.
Self hosted would be the preferred option.

I hope this makes sense :slight_smile:

That is a tough one. We used a tamper evident seal and GPS tracking on the business resumption plans here at work. There are 3 to 4 copies of the documentation in undisclosed locations to everyone, only officers know. Each one of the lockboxes has a coded lock and tamper evident seals. If the box is opened a GPS locator will activate and a tracking service will be notified.

As for who and how they set it up here at work. That is considered “confidential”.

If I was one of your clients, I would demand to have access to MY system whenever I wanted. If I mess it up, I would also expect you to charge me to fix it.

Every client should have a means to log into their system, it is their system after all. There are a few posts of “the next company” trying to break in and put things together after an MSP is fired and another hired, with no passwords or anything.

I suggest making an account on all equipment with a very long random password, and printing it on good paper (no cheap inkjet here, use something fairly archival). Tell them to lock this in a safe place. If you want to charge a small fee to cover your time to create this, then charge away, just don’t soak them for cash. This includes highest level admin and the local AD restore password to log in if things have gone really badly. You should also mention that this is a security risk, they should guard this document like any other business secret.

Again, if it was me, this would be in the terms of the contract. If you didn’t agree, I’d find another company. You are in effect holding their system (and data) hostage.

I’m sure some people will disagree with what I say, but that proves there are dumb customers out there who will give third parties the means to shut down their business at a whim or price increase.

I would be happy to hear from other MSP’s on how they handle this with their customers. @LTS_Tom

We use Hudu which allows sharing with clients: