azureblog.co.uk
← cd ~/posts

Temporary Access Pass: onboarding users without a password

A Temporary Access Pass lets a new starter, or someone who's lost their phone, sign in once and set up a passkey or Authenticator. No temporary passwords sent by email.

2 min read⚠ checked 15 Oct 2025Entra ID · Passkeys · Security
Part 1 of 6 in Passwordless rollout
On this page
  1. What it is
  2. Turn it on
  3. Issue one with PowerShell
  4. Good practice
  5. Common scenarios
  6. Troubleshooting

The weakest moment in most identity setups is day one. A new starter gets a temporary password, often by email or text, and has to register before they've proven who they are. Lost-phone recovery has the same problem in reverse. A Temporary Access Pass () fixes both.

  1. 01Service desk verifies identity
  2. 02Issue a one-time TAP
  3. 03User signs in with the TAP
  4. 04Registers a passkey or Authenticator
  5. 05TAP expires
A TAP is a short-lived bridge to a strong method, never a method in its own right.

What it is

A TAP is a time-limited passcode issued by an admin. It satisfies strong authentication requirements, so the user can sign in and register passwordless methods such as a , or Microsoft Authenticator.

Service deskNew starterEntra IDVerifies identity on a videocall1Issues one-time TAP, 1 hour2Reads out the TAP3Signs in with TAP4Registers a passkey5TAP used up; passkey is nowthe sign-in method
A new starter's first day with a Temporary Access Pass.

Turn it on

In the Entra admin center, go to Protection → Authentication methods → Policies → Temporary Access Pass. Enable it for the right groups and set:

  • Lifetime: keep it short, such as one hour for onboarding.
  • One-time use: require it, so the pass can't be reused.
  • Length: the default is fine for most organisations.

Issue one with PowerShell

powershell
Connect-MgGraph -Scopes "UserAuthenticationMethod.ReadWrite.All"

$tap = New-MgUserAuthenticationTemporaryAccessPassMethod -UserId "new.starter@contoso.com" -BodyParameter @{
    lifetimeInMinutes = 60
    isUsableOnce      = $true
}
$tap.TemporaryAccessPass

Good practice

  • Verify identity first. A TAP is only as strong as the check done before issuing it: a video call with ID, a manager confirming in person, or HR onboarding data.
  • Deliver it separately. Read it out on the call or hand it over in person rather than emailing it.
  • Pair with a registration campaign so users are guided straight to a passkey.
  • Limit who can issue. The Authentication Administrator role can issue TAPs for most users; privileged users need a Privileged Authentication Administrator.
Bonus: TAP works with Windows and , so a new starter can set up a laptop and Windows Hello without ever having a password.

Common scenarios

ScenarioSuggested settings
New starterOne-time use, 1 to 8 hours, issued on day one after an identity check
Lost or new phoneOne-time use, 1 hour, after verifying the user by video or in person
Windows Autopilot setupOne-time use, long enough to cover the device setup
Locked-out adminIssued only by a Privileged Authentication Administrator

Troubleshooting

  • The user isn't offered the TAP option: check the Temporary Access Pass policy targets a group they're in.
  • "Pass has expired": passes have a fixed lifetime from when they're created, not from first use. Issue a new one.
  • Can't issue a pass for an admin: that needs the Privileged Authentication Administrator role.
  • TAP policy enabled for the right groups
  • One-time use required
  • Identity verification steps written down for the service desk
  • Registration campaign set up to steer users to passkeys
  • Audit log alert on TAP creation for admin accounts

This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.

Next in Passwordless rollout · part 2 of 6Synced passkeys and passkey profiles are now GA in Entra ID →