Product Security - Break Glass Access - Rafay Product Documentation

UI

Break Glass Access Configuration

Navigate to System -> Break Glass Access. "Local Access" Page appears by default

After selecting the user, the "Break Glass Groups" screen will be displayed

Once users are added to a group, the newly added group will be visible as shown below. Users can then perform operations on the resources defined for this specific group for the specified time duration. Org Admins can edit or delete this access using the appropriate icons.

Note: - A user can be added to one or more groups based on access requirements - Break Glass Access can be configured for a user who is both a local and SSO user

Similar to local users, Break Glass Access can also be configured for IDP users.

Access Audit

The Access Audits page for Break Glass Access is designed to provide visibility into all actions and events related to break glass access within an organization. It serves as a centralized log where administrators can monitor activities such as updates to access groups or changes performed by users. This level of monitoring helps in quickly identifying any unauthorized or unexpected access, ensuring that only permitted actions are carried out.