Skip to main content

Ardoq Breakglass Procedure

How to prepare continued access to Ardoq in the event of a disaster recovery

D
Written by David Russell

What is this for?

While we highly encourage customers to use SSO for improved security and faster onboarding, a disaster recovery process may involve your SSO system being unavailable. How can you gain access to Ardoq, if plain login has been disabled? That is what the breakglass procedure is for.

High level overview

In a breakglass scenario, your goal is to gain access to the platform in order to contact tech support and then gain access to your primary account. To achieve this, you will:

  1. Login as one of your breakglass users.

  2. File a ticket with Ardoq's Technical Customer Support to request to enable plain login for the rest of your organization.

  3. Login to your primary account.

We highly recommend NOT to use an admin account as your breakglass user, due to the principle of least privilege.

Your goal with the breakglass procedure is to securely get in touch with customer support, in order to proceed to step 3.

How do you set it up?

These steps must be followed before your breakglass users will be activated.

  1. First, contact Ardoq's Technical Customer Support and inform them:

    1. Which accounts you want recorded as your breakglass accounts.

    2. Which organizations they should be breakglass accounts for (e.g. production, sandbox, etc)

  2. Ardoq will tag these specific users as breakglass accounts, and inform you that this step has been completed.

  3. You MUST set a unique password on each of these accounts. If they were auto-provisioned through SSO, then you will need to follow the "Forgot Password" flow in order to set the correct password. This can be found on the login page.


    1. As these accounts will always have username & password access to Ardoq, we strongly recommend setting the strongest possible password for these accounts.


  4. Document these usernames & passwords, and keep them safe and secure. These records will ensure you can access Ardoq in the future in a breakglass scenario.

⚠️ Ensure that you have set, and documented, the passwords to each of your breakglass accounts ⚠️

How do you activate the breakglass procedure?

  1. Navigate to the breakglass login page for your Ardoq domain, by setting "breakglass=true" in the URL.

    1. For example, if your normal login domain is acmecorp:

    2. You will navigate to:

  2. With the username and password of one of your breakglass accounts, login to Ardoq. Note that only breakglass accounts can login from the breakglass login page.

  3. File a ticket with Ardoq's Technical Customer Support to enable plain login for your organization. This can be short-lived, and disabled once you login to your primary account.

  4. Once Ardoq's Technical Customer Support enables plain login (typically within a few minutes), login to your primary account.

  5. (Optional) Now that you have access to your primary account, request that plain login is disabled for your organization.

    However, note that if the session on your primary account expires, you will need to follow the steps over again from step 1, including asking tech support to re-enable plain login.

What happens next?

Once your incident has recovered, you can safely keep plainlogin disabled and resume logging in through SSO as normal.

We highly recommend rotating your break glass passwords and updating your records with the updated credentials.

Did this answer your question?