User Has No Phone Yet? Create Temporary Access Pass

Published on:

A user may need to sign in before they have registered Microsoft Authenticator or another MFA method.

This often happens during onboarding, device replacement, or when a user gets a new phone.

In Microsoft Entra ID, this can be solved with a Temporary Access Pass.

A Temporary Access Pass is a time-limited sign-in method that allows the user to access the account and register stronger authentication methods.

Open Authentication Methods Policy

Go to:

Microsoft Entra ID > Protection > Authentication methods > Policies

Open:

Temporary Access Pass

Before a TAP can be used, the method must be enabled in the Authentication methods policy.

Microsoft Entra Authentication methods policy page showing Temporary Access Pass as an available authentication method

Enable Temporary Access Pass

Enable the Temporary Access Pass method.

Choose whether it applies to:

All users
Selected users or groups

For production, a selected pilot or onboarding group is usually safer than enabling it for everyone.

Microsoft Entra Temporary Access Pass policy enabled for selected users or groups

Configure TAP Settings

Temporary Access Pass can be configured with restrictions such as:

Default lifetime
Minimum lifetime
Maximum lifetime
One-time use
Length

For onboarding, a short lifetime is usually best.

The goal is not to create a permanent sign-in method.

The goal is to give the user temporary access so they can register Microsoft Authenticator or another strong method.

Microsoft Entra Temporary Access Pass settings showing lifetime and usage configuration

Create a Temporary Access Pass for the User

Go to:

Microsoft Entra ID > Users > Select user > Authentication methods

Select:

Add authentication method

Choose:

Temporary Access Pass

Then create the pass.

The TAP is created from the selected user’s Authentication methods page.

Microsoft Entra user Authentication methods page showing the option to add a new authentication method

Copy the Temporary Access Pass

After the TAP is created, copy it immediately and provide it to the user through a secure channel.

The pass is temporary and should be handled like a sensitive credential.

Microsoft Entra Temporary Access Pass created for the user showing the generated temporary pass

User Registers MFA

The user signs in with the Temporary Access Pass and then registers a permanent authentication method, for example:

Microsoft Authenticator
Passkey
FIDO2 security key

After registration, the user should use the permanent method instead of the Temporary Access Pass.

Result

The user can sign in even without a phone or existing MFA method.

Temporary Access Pass solves the onboarding problem without weakening long-term security. Once the user registers a permanent method, the temporary pass is no longer the normal sign-in path.