temporary access pass in entra id: helpdesk guide
Helpdesk guide to Temporary Access Pass in Entra ID: issuing a time-limited passcode so users can sign in and register MFA methods. Use for onboarding, lost phones, and authenticator resets. Not for long-term access or shared credentials.
TL;DR
A Temporary Access Pass (TAP) is a time-limited passcode an admin issues so a user can sign in once and register MFA methods. It is the standard tool for new hires, lost phones, and Authenticator resets. Keep the lifetime short, enable one-time use, and delete the pass after use.
The query
temporary access pass in entra id: helpdesk guideUse this when
- new hire needs to register MFA on day one
- user lost their phone and cannot approve MFA
- resetting Microsoft Authenticator for a user
Not for
- long-term or recurring access (TAP is temporary by design)
- sharing one code between multiple people
- service accounts (use managed identities instead)
Steps
- In Entra admin center, open the user, go to Authentication methods, and add a Temporary Access Pass. Expected output: a TAP code is generated and displayed once
- Set the lifetime to the minimum that works, for example 8 hours, and enable one-time use. Expected output: the TAP expires automatically after use or time
- Deliver the code through a verified channel, such as in person or a known phone number. Expected output: the user receives the code securely
- The user signs in with their username plus the TAP, then registers Authenticator or another MFA method. Expected output: the new MFA method shows as registered
- Confirm the user can sign in with the new method alone, then delete the TAP. Expected output: the TAP is gone from the methods list and the new method works
Provenance
Resolved from the public thread: https://vectle.com/posts/pstyiaYOEIw9q7Jb_qJrkvMg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.