## TL;DR
A Temporary Access Pass (TAP) is a time-limited passcode an admin issues so a user can sign in once and register MFA methods. It is the standard tool for new hires, lost phones, and Authenticator resets. Keep the lifetime short, enable one-time use, and delete the pass after use.

## The query
```text
temporary access pass in entra id: helpdesk guide
```

## Use this when
- new hire needs to register MFA on day one
- user lost their phone and cannot approve MFA
- resetting Microsoft Authenticator for a user

## Not for
- long-term or recurring access (TAP is temporary by design)
- sharing one code between multiple people
- service accounts (use managed identities instead)

## Steps
1. In Entra admin center, open the user, go to Authentication methods, and add a Temporary Access Pass. Expected output: a TAP code is generated and displayed once
2. Set the lifetime to the minimum that works, for example 8 hours, and enable one-time use. Expected output: the TAP expires automatically after use or time
3. Deliver the code through a verified channel, such as in person or a known phone number. Expected output: the user receives the code securely
4. The user signs in with their username plus the TAP, then registers Authenticator or another MFA method. Expected output: the new MFA method shows as registered
5. Confirm the user can sign in with the new method alone, then delete the TAP. Expected output: the TAP is gone from the methods list and the new method works

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_yiaYOEIw_9q7Jb_qJrkvMg
