How to Enable Temporary Access Pass Without Enforcing It for Everyone in Microsoft Entra
Question details
The administrator needs to configure Temporary Access Pass (TAP) exclusively for selected users or groups, rather than deploying it globally across the tenant.

- Product
- Microsoft Entra
- Device & OS
- not provided
- Scenario
- Testing or gradually deploying TAP authentication for a limited subset of users to ensure security protocols are met before a wider rollout.
- Observed behavior
- The administrator wants to avoid organization-wide enforcement while allowing targeted individuals or groups to utilize TAP for secure access.
Ensure you have at least the Authentication Policy Administrator role assigned in your Microsoft Entra tenant before attempting to modify authentication methods.
Configuring Temporary Access Pass for Specific Users or Groups
Apply the Temporary Access Pass policy to selected groups to test functionality and provide secure access without affecting the whole organization.
By default, enabling a new authentication policy might apply to 'All users' if not configured carefully. Limiting the assignment to specific groups allows administrators to execute a phased rollout.
Sign in to the Microsoft Entra admin center. Navigate to Protection > Authentication methods > Policies in the left-hand navigation menu.
Locate and click on 'Temporary Access Pass' from the list of available authentication methods to open its configuration pane.
Toggle the Enable switch to turn on the Temporary Access Pass policy for your tenant.
Under the Assignments section, choose the 'Select users and groups' option instead of 'All users'. Search for and select the specific groups or users you want to test.
Adjust the TAP settings (such as minimum/maximum lifetime and length) according to your security requirements, then click Save to apply the changes.

Manage Your IT Documentation Seamlessly with WPS Office
While managing enterprise security like Microsoft Entra policies, you need a reliable office suite for your IT documentation and deployment plans. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office with a familiar user interface.
- 1. Download and Install: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Open Your IT Documents: Easily open existing Microsoft Office documentation files (.docx, .xlsx) without losing any formatting or layouts.
- 3. Edit and Share Securely: Utilize the built-in PDF tools to export your Entra configuration guides and share them with your IT department.

Frequently Asked Questions
Can I set different TAP lifetimes for different user groups?
No, the Temporary Access Pass policy settings, such as minimum and maximum lifetime, apply globally to all users included in the policy assignment. You cannot configure separate lengths for different groups within the same tenant.
What roles are required to generate a Temporary Access Pass for a user?
To create a Temporary Access Pass for a standard user, you need to be an Authentication Administrator. The Privileged Authentication Administrator role is required if you are creating a TAP for other highly privileged administrators.
Can a Temporary Access Pass be used multiple times?
Yes, during the configuration of the TAP policy, administrators can specify whether the generated pass is strictly valid for a one-time use or if it can be used multiple times during its configured lifetime.
How does an end-user sign in using a Temporary Access Pass?
Users navigate to the standard Microsoft sign-in page, enter their User Principal Name (UPN), and will be prompted to enter their Temporary Access Pass instead of a password or their standard MFA method.




