Entra IDHow-to

Temporary Access Pass: onboarding users to passwordless and Windows Hello for Business

Enable the Temporary Access Pass policy, issue passes in the portal or with Graph PowerShell, and use them to register passkeys, Authenticator and Windows Hello for Business.

New starters and users who've lost their only MFA method have the same chicken-and-egg problem: they need a strong credential to register a strong credential. A Temporary Access Pass (TAP) solves it with a time-limited passcode that Microsoft Entra ID accepts for sign-in. Here's how to enable it, issue passes, use them for passkeys and Windows Hello for Business, and stop TAP from becoming a weak spot.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Enable the TAP policy; Create a pass; Use it to go passwordless; Revoke the pass). 3. Verify. 4. Tips & gotchas. Toolbox: Revoke-MgUserSignInSession, dsregcmd /status, Authentication methods › Policies, Entra ID › Users, IsUsable.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Enable the TAP policy2Create a pass3Use it to go passwordless4Revoke the passTOOLBOXRevoke-MgUserSignInSessiondsregcmd /statusAuthentication methods › PoliciesEntra ID › UsersIsUsableHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (4 steps: Enable the TAP policy; Create a pass; Use it to go passwordless; Revoke the pass). 3. Verify. 4. Tips & gotchas. Toolbox: Revoke-MgUserSignInSession, dsregcmd /status, Authentication methods › Policies, Entra ID › Users, IsUsable.1Prerequisites2Step-by-step1Enable the TAP policy2Create a pass3Use it to go passwordless4Revoke the pass3Verify4Tips & gotchasTOOLBOXRevoke-MgUserSignInSessiondsregcmd /statusAuthentication methods › PoliciesEntra ID › UsersIsUsable
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

Prerequisites#

  • Roles: Authentication Policy Administrator to enable and configure the policy. Authentication Administrators can create, view and delete passes for member users; Privileged Authentication Administrators can also do it for admins. Neither can create one for themselves.
  • Scope: you can create a TAP for anyone, but only users included in the TAP policy can sign in with it.
  • Target methods: passkeys (FIDO2) and/or Microsoft Authenticator enabled in the Authentication methods policy, and Windows Hello for Business configured if you'll use TAP during Windows setup.
  • Scripting: the Microsoft Graph PowerShell SDK with the UserAuthenticationMethod.ReadWrite.All permission.

Step 1: Enable the TAP policy#

  1. In the Microsoft Entra admin center, go to Entra ID › Authentication methods › Policies and select Temporary Access Pass.
  2. Enable it and include a group. An onboarding or helpdesk-recovery group keeps the scope tight.
  3. Select Configure to review the settings, then Save.
SettingDefaultAllowed values
Minimum lifetime1 hour10 minutes to 30 days
Maximum lifetime8 hours10 minutes to 30 days
Default lifetime1 hour10 minutes to 30 days; individual passes can override it within the min/max
One-time useNoYes makes every pass in the tenant single use
Length8 characters8 to 48 characters

Step 2: Create a pass#

In the admin center#

Go to Entra ID › Users, open the user, select Authentication methods › Add authentication method and choose Temporary Access Pass. Set a custom activation time or duration and select Add. Copy the value straight away: it can't be shown again once you select OK.

With Microsoft Graph PowerShell#

PowerShell
Connect-MgGraph -Scopes "UserAuthenticationMethod.ReadWrite.All"

$params = @{
    isUsableOnce      = $true
    lifetimeInMinutes = 60
}
$tap = New-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com" -BodyParameter $params
$tap.TemporaryAccessPass   # only returned at creation time

The lifetime must sit between the policy's minimum and maximum. Each user can have only one TAP, and creating a new one replaces the existing pass. Later, Get-MgUserAuthenticationTemporaryAccessPassMethod shows IsUsable and MethodUsabilityReason without revealing the code.

Step 3: Use it to go passwordless#

Passkeys and Microsoft Authenticator#

The user opens Security info (aka.ms/mysecurityinfo), enters their UPN, gets a TAP prompt instead of a password prompt, and registers a passkey or Authenticator. In the Authenticator app, they can also add their work account, sign in with the TAP, and register a passkey or phone sign-in directly. In federated domains, a TAP user authenticates in Entra ID instead of being redirected to the federated identity provider.

Watch out: after signing in with a one-time TAP, the user must finish registering the new method within 10 minutes. Have the security key or phone ready before they start.

Windows setup and Windows Hello for Business#

  • Microsoft Entra join during setup (OOBE or Autopilot): the user can authenticate with the TAP, no password needed, to join the device and set up Windows Hello for Business.
  • Already-joined devices: the user first signs in with another method (password, smart card or FIDO2 key), then uses the TAP to set up Windows Hello. With web sign-in enabled, a TAP can also sign in to Windows, but that's intended for initial setup or recovery only.
  • Hybrid joined devices: another method is always needed first.

If you enforce one-time passes and enrollment reaches the Windows Hello step after more than 10 minutes, the user needs a second TAP. A short multi-use pass avoids that, but monitor how often it's used.

Step 4: Revoke the pass#

Once the user has a passwordless method, remove the TAP: open the user's Authentication methods and select Delete next to the Temporary Access Pass, or use PowerShell:

PowerShell
$tap = Get-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com"
Remove-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com" -TemporaryAccessPassAuthenticationMethodId $tap.Id

If you suspect misuse, also revoke the user's sessions with Revoke-MgUserSignInSession and review which methods were registered while the pass was valid.

Verify#

  • The user's Authentication methods page lists the new passkey, Authenticator or Windows Hello for Business method.
  • On Windows, dsregcmd /status run as the user shows NgcSet : YES once Windows Hello is set up.
  • The user can sign in with the new method. After you delete the pass, allow a few minutes for replication before the TAP prompt stops appearing.

Tips & gotchas#

  • Verify identity before you issue. A TAP lets its holder register credentials, so treat issuing one like a password reset and deliver it through a trusted channel.
  • Short and single use by default. Use multi-use passes only where device setup needs them.
  • Expiry doesn't end sessions. Tokens issued from a TAP sign-in are capped at the pass expiry when issued, but an expired TAP doesn't invalidate sessions already established. Use the sign-in frequency control to bound them.
  • Not supported everywhere: TAP doesn't work with the NPS extension or the AD FS adapter, and only internal guests can be issued one.
  • Registration policies: users in scope of the SSPR registration policy or the ID Protection MFA registration policy get the combined registration interrupt after a browser TAP sign-in, and that flow doesn't support FIDO2 or phone sign-in registration.
  • Replication: allow a few minutes after creating a pass before the TAP prompt appears.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)