Temporary Access Pass: onboarding users without a password
A Temporary Access Pass lets a new starter, or someone who's lost their phone, sign in once and set up a passkey or Authenticator. No temporary passwords sent by email.
On this page
The weakest moment in most identity setups is day one. A new starter gets a temporary password, often by email or text, and has to register MFA before they've proven who they are. Lost-phone recovery has the same problem in reverse. A Temporary Access Pass (TAP) fixes both.
- 01Service desk verifies identity
- 02Issue a one-time TAP
- 03User signs in with the TAP
- 04Registers a passkey or Authenticator
- 05TAP expires
What it is
A TAP is a time-limited passcode issued by an admin. It satisfies strong authentication requirements, so the user can sign in and register passwordless methods such as a passkey, Windows Hello for Business or Microsoft Authenticator.
Turn it on
In the Entra admin center, go to Protection → Authentication methods → Policies → Temporary Access Pass. Enable it for the right groups and set:
- Lifetime: keep it short, such as one hour for onboarding.
- One-time use: require it, so the pass can't be reused.
- Length: the default is fine for most organisations.
Issue one with PowerShell
Connect-MgGraph -Scopes "UserAuthenticationMethod.ReadWrite.All"
$tap = New-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com" -BodyParameter @{
lifetimeInMinutes = 60
isUsableOnce = $true
}
$tap.TemporaryAccessPassGood practice
- Verify identity first. A TAP is only as strong as the check done before issuing it: a video call with ID, a manager confirming in person, or HR onboarding data.
- Deliver it separately. Read it out on the call or hand it over in person rather than emailing it.
- Pair with a registration campaign so users are guided straight to a passkey.
- Limit who can issue. The Authentication Administrator role can issue TAPs for most users; privileged users need a Privileged Authentication Administrator.
Common scenarios
| Scenario | Suggested settings |
|---|---|
| New starter | One-time use, 1 to 8 hours, issued on day one after an identity check |
| Lost or new phone | One-time use, 1 hour, after verifying the user by video or in person |
| Windows Autopilot setup | One-time use, long enough to cover the device setup |
| Locked-out admin | Issued only by a Privileged Authentication Administrator |
Troubleshooting
- The user isn't offered the TAP option: check the Temporary Access Pass policy targets a group they're in.
- "Pass has expired": passes have a fixed lifetime from when they're created, not from first use. Issue a new one.
- Can't issue a pass for an admin: that needs the Privileged Authentication Administrator role.
- TAP policy enabled for the right groups
- One-time use required
- Identity verification steps written down for the service desk
- Registration campaign set up to steer users to passkeys
- Audit log alert on TAP creation for admin accounts
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.
Next in Passwordless rollout · part 2 of 6Synced passkeys and passkey profiles are now GA in Entra ID →