logo
search
MFA Security Issues

How to Enable Temporary Access Pass Without Enforcing It for Everyone in Microsoft Entra

Muhammad TalhaMuhammad Talha Sep 25, 2026 869 views

Question details

The administrator needs to configure Temporary Access Pass (TAP) exclusively for selected users or groups, rather than deploying it globally across the tenant.

How to Enable Temporary Access Pass for Selected Users in Microsoft Entra
Product
Microsoft Entra
Device & OS
not provided
Scenario
Testing or gradually deploying TAP authentication for a limited subset of users to ensure security protocols are met before a wider rollout.
Observed behavior
The administrator wants to avoid organization-wide enforcement while allowing targeted individuals or groups to utilize TAP for secure access.
Before you start

Ensure you have at least the Authentication Policy Administrator role assigned in your Microsoft Entra tenant before attempting to modify authentication methods.

Solution 1Recommended

Configuring Temporary Access Pass for Specific Users or Groups

Apply the Temporary Access Pass policy to selected groups to test functionality and provide secure access without affecting the whole organization.

By default, enabling a new authentication policy might apply to 'All users' if not configured carefully. Limiting the assignment to specific groups allows administrators to execute a phased rollout.

1
Access Authentication Policies

Sign in to the Microsoft Entra admin center. Navigate to Protection > Authentication methods > Policies in the left-hand navigation menu.

2
Select Temporary Access Pass

Locate and click on 'Temporary Access Pass' from the list of available authentication methods to open its configuration pane.

3
Enable the Policy

Toggle the Enable switch to turn on the Temporary Access Pass policy for your tenant.

4
Assign Specific Targets

Under the Assignments section, choose the 'Select users and groups' option instead of 'All users'. Search for and select the specific groups or users you want to test.

5
Configure Settings and Save

Adjust the TAP settings (such as minimum/maximum lifetime and length) according to your security requirements, then click Save to apply the changes.

Configuring Temporary Access Pass for Specific Users or Groups
Policy Propagation Time: It may take a few minutes for the new authentication policy to propagate and become available for the assigned users to use.
Free Microsoft Office alternative

Manage Your IT Documentation Seamlessly with WPS Office

While managing enterprise security like Microsoft Entra policies, you need a reliable office suite for your IT documentation and deployment plans. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office with a familiar user interface.

  1. 1. Download and Install: Visit the official WPS Office website and download the free installer for your operating system.
  2. 2. Open Your IT Documents: Easily open existing Microsoft Office documentation files (.docx, .xlsx) without losing any formatting or layouts.
  3. 3. Edit and Share Securely: Utilize the built-in PDF tools to export your Entra configuration guides and share them with your IT department.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation that consumes fewer system resources on admin workstations.Free to use with a familiar tabbed interface, ensuring zero learning curve for IT teams.Built-in PDF editing tools for creating and securely sharing enterprise security guidelines.
microsoft office alternative - wps office

Frequently Asked Questions

Can I set different TAP lifetimes for different user groups?

No, the Temporary Access Pass policy settings, such as minimum and maximum lifetime, apply globally to all users included in the policy assignment. You cannot configure separate lengths for different groups within the same tenant.

What roles are required to generate a Temporary Access Pass for a user?

To create a Temporary Access Pass for a standard user, you need to be an Authentication Administrator. The Privileged Authentication Administrator role is required if you are creating a TAP for other highly privileged administrators.

Can a Temporary Access Pass be used multiple times?

Yes, during the configuration of the TAP policy, administrators can specify whether the generated pass is strictly valid for a one-time use or if it can be used multiple times during its configured lifetime.

How does an end-user sign in using a Temporary Access Pass?

Users navigate to the standard Microsoft sign-in page, enter their User Principal Name (UPN), and will be prompted to enter their Temporary Access Pass instead of a password or their standard MFA method.