New starters and users who've lost their only MFA method have the same chicken-and-egg problem: they need a strong credential to register a strong credential. A Temporary Access Pass (TAP) solves it with a time-limited passcode that Microsoft Entra ID accepts for sign-in. Here's how to enable it, issue passes, use them for passkeys and Windows Hello for Business, and stop TAP from becoming a weak spot.
Prerequisites#
- Roles: Authentication Policy Administrator to enable and configure the policy. Authentication Administrators can create, view and delete passes for member users; Privileged Authentication Administrators can also do it for admins. Neither can create one for themselves.
- Scope: you can create a TAP for anyone, but only users included in the TAP policy can sign in with it.
- Target methods: passkeys (FIDO2) and/or Microsoft Authenticator enabled in the Authentication methods policy, and Windows Hello for Business configured if you'll use TAP during Windows setup.
- Scripting: the Microsoft Graph PowerShell SDK with the
UserAuthenticationMethod.ReadWrite.Allpermission.
Step 1: Enable the TAP policy#
- In the Microsoft Entra admin center, go to Entra ID › Authentication methods › Policies and select Temporary Access Pass.
- Enable it and include a group. An onboarding or helpdesk-recovery group keeps the scope tight.
- Select Configure to review the settings, then Save.
| Setting | Default | Allowed values |
|---|---|---|
| Minimum lifetime | 1 hour | 10 minutes to 30 days |
| Maximum lifetime | 8 hours | 10 minutes to 30 days |
| Default lifetime | 1 hour | 10 minutes to 30 days; individual passes can override it within the min/max |
| One-time use | No | Yes makes every pass in the tenant single use |
| Length | 8 characters | 8 to 48 characters |
Step 2: Create a pass#
In the admin center#
Go to Entra ID › Users, open the user, select Authentication methods › Add authentication method and choose Temporary Access Pass. Set a custom activation time or duration and select Add. Copy the value straight away: it can't be shown again once you select OK.
With Microsoft Graph PowerShell#
Connect-MgGraph -Scopes "UserAuthenticationMethod.ReadWrite.All"
$params = @{
isUsableOnce = $true
lifetimeInMinutes = 60
}
$tap = New-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com" -BodyParameter $params
$tap.TemporaryAccessPass # only returned at creation timeThe lifetime must sit between the policy's minimum and maximum. Each user can have only one TAP, and creating a new one replaces the existing pass. Later, Get-MgUserAuthenticationTemporaryAccessPassMethod shows IsUsable and MethodUsabilityReason without revealing the code.
Step 3: Use it to go passwordless#
Passkeys and Microsoft Authenticator#
The user opens Security info (aka.ms/mysecurityinfo), enters their UPN, gets a TAP prompt instead of a password prompt, and registers a passkey or Authenticator. In the Authenticator app, they can also add their work account, sign in with the TAP, and register a passkey or phone sign-in directly. In federated domains, a TAP user authenticates in Entra ID instead of being redirected to the federated identity provider.
Watch out: after signing in with a one-time TAP, the user must finish registering the new method within 10 minutes. Have the security key or phone ready before they start.
Windows setup and Windows Hello for Business#
- Microsoft Entra join during setup (OOBE or Autopilot): the user can authenticate with the TAP, no password needed, to join the device and set up Windows Hello for Business.
- Already-joined devices: the user first signs in with another method (password, smart card or FIDO2 key), then uses the TAP to set up Windows Hello. With web sign-in enabled, a TAP can also sign in to Windows, but that's intended for initial setup or recovery only.
- Hybrid joined devices: another method is always needed first.
If you enforce one-time passes and enrollment reaches the Windows Hello step after more than 10 minutes, the user needs a second TAP. A short multi-use pass avoids that, but monitor how often it's used.
Step 4: Revoke the pass#
Once the user has a passwordless method, remove the TAP: open the user's Authentication methods and select Delete next to the Temporary Access Pass, or use PowerShell:
$tap = Get-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com"
Remove-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com" -TemporaryAccessPassAuthenticationMethodId $tap.IdIf you suspect misuse, also revoke the user's sessions with Revoke-MgUserSignInSession and review which methods were registered while the pass was valid.
Verify#
- The user's Authentication methods page lists the new passkey, Authenticator or Windows Hello for Business method.
- On Windows,
dsregcmd /statusrun as the user showsNgcSet : YESonce Windows Hello is set up. - The user can sign in with the new method. After you delete the pass, allow a few minutes for replication before the TAP prompt stops appearing.
Tips & gotchas#
- Verify identity before you issue. A TAP lets its holder register credentials, so treat issuing one like a password reset and deliver it through a trusted channel.
- Short and single use by default. Use multi-use passes only where device setup needs them.
- Expiry doesn't end sessions. Tokens issued from a TAP sign-in are capped at the pass expiry when issued, but an expired TAP doesn't invalidate sessions already established. Use the sign-in frequency control to bound them.
- Not supported everywhere: TAP doesn't work with the NPS extension or the AD FS adapter, and only internal guests can be issued one.
- Registration policies: users in scope of the SSPR registration policy or the ID Protection MFA registration policy get the combined registration interrupt after a browser TAP sign-in, and that flow doesn't support FIDO2 or phone sign-in registration.
- Replication: allow a few minutes after creating a pass before the TAP prompt appears.