{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/entra-temporary-access-pass-bootstrap-control/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/",
        "slug": "entra-temporary-access-pass-bootstrap-control",
        "url": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/entra-temporary-access-pass-bootstrap-control/"
        },
        "title": "Issue Microsoft Entra Temporary Access Passes as controlled bootstrap credentials",
        "summary": "A Temporary Access Pass can bootstrap passwordless registration or recovery, but its scope, delivery, lifetime, use count, and follow-up evidence need the same care as any other powerful temporary credential.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:26+00:00",
        "modified_at": "2026-08-25T21:36:18+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 619,
        "potentially_affected": "Microsoft Entra users, authentication administrators, passwordless enrollment, account recovery, device enrollment, federated domains, and Conditional Access session design.",
        "dse_recommendation": "Authorize each Temporary Access Pass for a named purpose, issue it through a verified support workflow, deliver it separately from routine account communications, and confirm both method registration and pass retirement.",
        "primary_source": {
            "name": "Configure Temporary Access Pass to register passwordless authentication methods",
            "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> Microsoft Entra Temporary Access Pass (TAP) is a time-limited passcode for bootstrapping passwordless authentication or helping a user recover when a strong method is unavailable. It is still a usable sign-in credential. Treat its creation, delivery, use, and removal as a controlled identity operation rather than a convenience code sent through an unverified support channel.</p>\n<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft&#8217;s <a href=\"https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass\" target=\"_blank\" rel=\"noopener noreferrer\">Temporary Access Pass guidance</a> says a TAP can be configured for one use or multiple sign-ins. A user can use it to register methods such as a passkey, FIDO2 security key, Windows Hello for Business, or Microsoft Authenticator. In a federated domain, TAP authentication is completed by Microsoft Entra instead of redirecting the user to the federated identity provider.</p>\n<p>The authentication methods policy controls which users may sign in with TAP and sets parameters such as minimum, maximum, and default lifetime, one-time-use behavior, and passcode length. Microsoft distinguishes the role used to manage the tenant policy from roles that can create, view, or delete a user&#8217;s TAP. The actual passcode is displayed when it is created and cannot be viewed again after the administrator closes that display.</p>\n<p>Microsoft also documents important boundaries. A user can have only one TAP at a time. A TAP issued to an external guest is not supported, although an external guest may use a TAP issued by the home tenant when cross-tenant requirements are satisfied. An expired or deleted TAP cannot be used for new authentication, but expiration does not retroactively terminate every already-established session. Conditional Access session controls can therefore affect how long access obtained through the sign-in continues.</p>\n<h2>What the source does not establish</h2>\n<p>The Microsoft page does not verify the requester&#8217;s identity, authorize a help-desk action, select a safe delivery channel, or prove that the intended user received the code. It does not make TAP an appropriate response to every lost-device, new-hire, or recovery scenario. A short lifetime does not compensate for weak requester verification, excessive administrator access, or an unmonitored handoff.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Which onboarding and recovery cases are approved to use TAP, and which require escalation?</li>\n<li>How will the operator verify the person and the authorized request without relying on a compromised method?</li>\n<li>Will one-time use work for the enrollment path, including device setup and passwordless registration timing?</li>\n<li>Which administrators can manage the policy or issue passes, and how are their actions reviewed?</li>\n<li>Does Conditional Access limit session duration appropriately after TAP authentication?</li>\n</ul>\n<h2>DSE recommendation: controlled next steps</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<ol>\n<li>Define approved TAP scenarios, identity-proofing steps, authorizers, administrator roles, delivery channels, maximum lifetimes, and escalation triggers.</li>\n<li>Pilot the complete enrollment and recovery journey with test identities. Include federated users, managed-device enrollment, delayed registration, and a failed or expired pass.</li>\n<li>Verify the requester through an approved independent process before creation. Record the request, purpose, operator, start time, duration, and whether the pass is single-use.</li>\n<li>Deliver the pass through a channel selected for the assessed risk. Avoid placing the TAP beside enough account context for an unintended recipient to use it.</li>\n<li>Require the user to register the intended strong method, remove obsolete methods when authorized, and report completion through the support workflow.</li>\n<li>Delete an unused or no-longer-needed TAP and investigate unexplained issuance, repeated failures, or registration outside the approved window.</li>\n</ol>\n<h2>Verification and evidence</h2>\n<ul>\n<li>Preserve the approved request and administrator audit event without recording the TAP value.</li>\n<li>Confirm the intended authentication method is registered and usable.</li>\n<li>Confirm the TAP is expired, consumed, replaced, or deleted as designed.</li>\n<li>Review sign-in evidence for unexpected resources, locations, devices, or continued sessions.</li>\n<li>Record exceptions and the person who accepted any remaining exposure.</li>\n</ul>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass\" target=\"_blank\" rel=\"noopener noreferrer\">Configure Temporary Access Pass to register passwordless authentication methods</a> — Microsoft</li>\n</ul>",
        "content_text": "Bottom line: Microsoft Entra Temporary Access Pass (TAP) is a time-limited passcode for bootstrapping passwordless authentication or helping a user recover when a strong method is unavailable. It is still a usable sign-in credential. Treat its creation, delivery, use, and removal as a controlled identity operation rather than a convenience code sent through an unverified support channel.\nSource fact: what Microsoft documents\nMicrosoft’s Temporary Access Pass guidance says a TAP can be configured for one use or multiple sign-ins. A user can use it to register methods such as a passkey, FIDO2 security key, Windows Hello for Business, or Microsoft Authenticator. In a federated domain, TAP authentication is completed by Microsoft Entra instead of redirecting the user to the federated identity provider.\nThe authentication methods policy controls which users may sign in with TAP and sets parameters such as minimum, maximum, and default lifetime, one-time-use behavior, and passcode length. Microsoft distinguishes the role used to manage the tenant policy from roles that can create, view, or delete a user’s TAP. The actual passcode is displayed when it is created and cannot be viewed again after the administrator closes that display.\nMicrosoft also documents important boundaries. A user can have only one TAP at a time. A TAP issued to an external guest is not supported, although an external guest may use a TAP issued by the home tenant when cross-tenant requirements are satisfied. An expired or deleted TAP cannot be used for new authentication, but expiration does not retroactively terminate every already-established session. Conditional Access session controls can therefore affect how long access obtained through the sign-in continues.\nWhat the source does not establish\nThe Microsoft page does not verify the requester’s identity, authorize a help-desk action, select a safe delivery channel, or prove that the intended user received the code. It does not make TAP an appropriate response to every lost-device, new-hire, or recovery scenario. A short lifetime does not compensate for weak requester verification, excessive administrator access, or an unmonitored handoff.\nApplicability questions\n\nWhich onboarding and recovery cases are approved to use TAP, and which require escalation?\nHow will the operator verify the person and the authorized request without relying on a compromised method?\nWill one-time use work for the enrollment path, including device setup and passwordless registration timing?\nWhich administrators can manage the policy or issue passes, and how are their actions reviewed?\nDoes Conditional Access limit session duration appropriately after TAP authentication?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nDefine approved TAP scenarios, identity-proofing steps, authorizers, administrator roles, delivery channels, maximum lifetimes, and escalation triggers.\nPilot the complete enrollment and recovery journey with test identities. Include federated users, managed-device enrollment, delayed registration, and a failed or expired pass.\nVerify the requester through an approved independent process before creation. Record the request, purpose, operator, start time, duration, and whether the pass is single-use.\nDeliver the pass through a channel selected for the assessed risk. Avoid placing the TAP beside enough account context for an unintended recipient to use it.\nRequire the user to register the intended strong method, remove obsolete methods when authorized, and report completion through the support workflow.\nDelete an unused or no-longer-needed TAP and investigate unexplained issuance, repeated failures, or registration outside the approved window.\n\nVerification and evidence\n\nPreserve the approved request and administrator audit event without recording the TAP value.\nConfirm the intended authentication method is registered and usable.\nConfirm the TAP is expired, consumed, replaced, or deleted as designed.\nReview sign-in evidence for unexpected resources, locations, devices, or continued sessions.\nRecord exceptions and the person who accepted any remaining exposure.\n\nOfficial references\n\nConfigure Temporary Access Pass to register passwordless authentication methods — Microsoft",
        "content_markdown": "Bottom line: Microsoft Entra Temporary Access Pass (TAP) is a time-limited passcode for bootstrapping passwordless authentication or helping a user recover when a strong method is unavailable. It is still a usable sign-in credential. Treat its creation, delivery, use, and removal as a controlled identity operation rather than a convenience code sent through an unverified support channel.\n\n## Source fact: what Microsoft documents\n\nMicrosoft’s [Temporary Access Pass guidance](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass) says a TAP can be configured for one use or multiple sign-ins. A user can use it to register methods such as a passkey, FIDO2 security key, Windows Hello for Business, or Microsoft Authenticator. In a federated domain, TAP authentication is completed by Microsoft Entra instead of redirecting the user to the federated identity provider.\n\nThe authentication methods policy controls which users may sign in with TAP and sets parameters such as minimum, maximum, and default lifetime, one-time-use behavior, and passcode length. Microsoft distinguishes the role used to manage the tenant policy from roles that can create, view, or delete a user’s TAP. The actual passcode is displayed when it is created and cannot be viewed again after the administrator closes that display.\n\nMicrosoft also documents important boundaries. A user can have only one TAP at a time. A TAP issued to an external guest is not supported, although an external guest may use a TAP issued by the home tenant when cross-tenant requirements are satisfied. An expired or deleted TAP cannot be used for new authentication, but expiration does not retroactively terminate every already-established session. Conditional Access session controls can therefore affect how long access obtained through the sign-in continues.\n\n## What the source does not establish\n\nThe Microsoft page does not verify the requester’s identity, authorize a help-desk action, select a safe delivery channel, or prove that the intended user received the code. It does not make TAP an appropriate response to every lost-device, new-hire, or recovery scenario. A short lifetime does not compensate for weak requester verification, excessive administrator access, or an unmonitored handoff.\n\n## Applicability questions\n\n- Which onboarding and recovery cases are approved to use TAP, and which require escalation?\n\n- How will the operator verify the person and the authorized request without relying on a compromised method?\n\n- Will one-time use work for the enrollment path, including device setup and passwordless registration timing?\n\n- Which administrators can manage the policy or issue passes, and how are their actions reviewed?\n\n- Does Conditional Access limit session duration appropriately after TAP authentication?\n\n## DSE recommendation: controlled next steps\n\nThe following steps are DSE recommendations based on the cited source.\n\n- Define approved TAP scenarios, identity-proofing steps, authorizers, administrator roles, delivery channels, maximum lifetimes, and escalation triggers.\n\n- Pilot the complete enrollment and recovery journey with test identities. Include federated users, managed-device enrollment, delayed registration, and a failed or expired pass.\n\n- Verify the requester through an approved independent process before creation. Record the request, purpose, operator, start time, duration, and whether the pass is single-use.\n\n- Deliver the pass through a channel selected for the assessed risk. Avoid placing the TAP beside enough account context for an unintended recipient to use it.\n\n- Require the user to register the intended strong method, remove obsolete methods when authorized, and report completion through the support workflow.\n\n- Delete an unused or no-longer-needed TAP and investigate unexplained issuance, repeated failures, or registration outside the approved window.\n\n## Verification and evidence\n\n- Preserve the approved request and administrator audit event without recording the TAP value.\n\n- Confirm the intended authentication method is registered and usable.\n\n- Confirm the TAP is expired, consumed, replaced, or deleted as designed.\n\n- Review sign-in evidence for unexpected resources, locations, devices, or continued sessions.\n\n- Record exceptions and the person who accepted any remaining exposure.\n\n## Official references\n\n- [Configure Temporary Access Pass to register passwordless authentication methods](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/",
                "url": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Issue Microsoft Entra Temporary Access Passes as controlled bootstrap credentials",
                        "item": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/#article",
                "identifier": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/",
                "url": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/",
                "headline": "Issue Microsoft Entra Temporary Access Passes as controlled bootstrap credentials",
                "description": "A Temporary Access Pass can bootstrap passwordless registration or recovery, but its scope, delivery, lifetime, use count, and follow-up evidence need…",
                "abstract": "A Temporary Access Pass can bootstrap passwordless registration or recovery, but its scope, delivery, lifetime, use count, and follow-up evidence need the same care as any other powerful temporary credential.",
                "articleBody": "Bottom line: Microsoft Entra Temporary Access Pass (TAP) is a time-limited passcode for bootstrapping passwordless authentication or helping a user recover when a strong method is unavailable. It is still a usable sign-in credential. Treat its creation, delivery, use, and removal as a controlled identity operation rather than a convenience code sent through an unverified support channel.\nSource fact: what Microsoft documents\nMicrosoft’s Temporary Access Pass guidance says a TAP can be configured for one use or multiple sign-ins. A user can use it to register methods such as a passkey, FIDO2 security key, Windows Hello for Business, or Microsoft Authenticator. In a federated domain, TAP authentication is completed by Microsoft Entra instead of redirecting the user to the federated identity provider.\nThe authentication methods policy controls which users may sign in with TAP and sets parameters such as minimum, maximum, and default lifetime, one-time-use behavior, and passcode length. Microsoft distinguishes the role used to manage the tenant policy from roles that can create, view, or delete a user’s TAP. The actual passcode is displayed when it is created and cannot be viewed again after the administrator closes that display.\nMicrosoft also documents important boundaries. A user can have only one TAP at a time. A TAP issued to an external guest is not supported, although an external guest may use a TAP issued by the home tenant when cross-tenant requirements are satisfied. An expired or deleted TAP cannot be used for new authentication, but expiration does not retroactively terminate every already-established session. Conditional Access session controls can therefore affect how long access obtained through the sign-in continues.\nWhat the source does not establish\nThe Microsoft page does not verify the requester’s identity, authorize a help-desk action, select a safe delivery channel, or prove that the intended user received the code. It does not make TAP an appropriate response to every lost-device, new-hire, or recovery scenario. A short lifetime does not compensate for weak requester verification, excessive administrator access, or an unmonitored handoff.\nApplicability questions\n\nWhich onboarding and recovery cases are approved to use TAP, and which require escalation?\nHow will the operator verify the person and the authorized request without relying on a compromised method?\nWill one-time use work for the enrollment path, including device setup and passwordless registration timing?\nWhich administrators can manage the policy or issue passes, and how are their actions reviewed?\nDoes Conditional Access limit session duration appropriately after TAP authentication?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nDefine approved TAP scenarios, identity-proofing steps, authorizers, administrator roles, delivery channels, maximum lifetimes, and escalation triggers.\nPilot the complete enrollment and recovery journey with test identities. Include federated users, managed-device enrollment, delayed registration, and a failed or expired pass.\nVerify the requester through an approved independent process before creation. Record the request, purpose, operator, start time, duration, and whether the pass is single-use.\nDeliver the pass through a channel selected for the assessed risk. Avoid placing the TAP beside enough account context for an unintended recipient to use it.\nRequire the user to register the intended strong method, remove obsolete methods when authorized, and report completion through the support workflow.\nDelete an unused or no-longer-needed TAP and investigate unexplained issuance, repeated failures, or registration outside the approved window.\n\nVerification and evidence\n\nPreserve the approved request and administrator audit event without recording the TAP value.\nConfirm the intended authentication method is registered and usable.\nConfirm the TAP is expired, consumed, replaced, or deleted as designed.\nReview sign-in evidence for unexpected resources, locations, devices, or continued sessions.\nRecord exceptions and the person who accepted any remaining exposure.\n\nOfficial references\n\nConfigure Temporary Access Pass to register passwordless authentication methods — Microsoft",
                "datePublished": "2026-08-25T21:35:26+00:00",
                "dateModified": "2026-08-25T21:36:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/entra-temporary-access-pass-bootstrap-control/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Issue Microsoft Entra Temporary Access Passes as controlled bootstrap credentials"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 619,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Temporary Access Pass to register passwordless authentication methods",
                    "url": "https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass"
                }
            }
        ]
    }
}