# Issue Microsoft Entra Temporary Access Passes with Persona

> Verify an employee with a government ID and selfie before Persona creates a Microsoft Entra Temporary Access Pass so they can sign in and recover access.

Source: https://help.withpersona.com/articles/4zIsYGZ62Hh6hmj4Ev6RVG/
Section: Marketplace and 3rd-Party Integrations > Authentication > Microsoft Entra

## About Microsoft Entra Temporary Access Pass

Microsoft Entra supports a [Temporary Access Pass](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass) (TAP). A TAP is a time-limited passcode that lets a user sign in when they can't use their usual authentication methods, for example when they lose their phone or forget their security key. Once signed in, the user can register new methods. An administrator creates the pass and hands it to the user, so your helpdesk has to confirm who is asking for it first.

With Persona, the employee proves who they are with a government ID and selfie verification. Persona compares the name on the ID with their Entra profile, and only then creates the Temporary Access Pass and shows it to the employee. This helps protect account recovery against social engineering, deepfakes, and account takeover, and your helpdesk never handles the pass.

### How it works

1.  Your helpdesk sends the employee a Persona verification link.
2.  Persona looks up the employee in Microsoft Entra by their user principal name (UPN).
3.  The employee completes a government ID and selfie verification. Persona compares the government ID with the employee's Entra profile.
4.  If the verification passes, Persona creates a Temporary Access Pass in Microsoft Entra and shows it on the final screen.
5.  The employee signs in to Microsoft with the pass and registers a new authentication method.

ℹ️

Use a Persona organization dedicated to your workforce, separate from any organization that verifies your customers, so employee and customer data stay apart. Ask your Persona contact if you don't have one yet.

## Microsoft Entra Configuration Guide

Follow the steps below to issue Microsoft Entra Temporary Access Passes with Persona. The [Microsoft Entra Temporary Access Pass wizard](https://app.withpersona.com/dashboard/solutions/workforce/temporary-access-pass/entra) in the Persona Dashboard walks you through the same steps and checks your setup as you go.

### 1\. Configure Persona Marketplace Integration for Employee Data

#### Context

Persona requires access to your Microsoft Entra tenant through Microsoft Graph, both to look up the employee and to create their Temporary Access Pass.

In order to ensure the employee being verified matches the Entra account being recovered, Persona compares the values extracted from the employee's government ID with the given name and surname stored in their Entra user profile.

ℹ️

Please ensure that the names that are stored in Entra are employee legal names, rather than preferred names or nicknames.

#### Connect Microsoft Entra

1.  Follow [Connect Microsoft Entra ID to your Persona account](https://help.withpersona.com/articles/6vHVa8KcEURyza3nk2v0RH/#connect-microsoft-entra-id-to-your-persona-account) to add a credential under **Integrations > Marketplace > Microsoft Entra ID** in the Persona Dashboard.
2.  Connect with an Entra administrator who can create a Temporary Access Pass for the employees in scope. An Authentication Administrator can create passes for members, and a Privileged Authentication Administrator can also create them for administrators. Persona creates each pass as this administrator, and Entra won't create one for that administrator's own account.
3.  Use **Test** to check the connection before continuing.

### 2\. Turn on the Temporary Access Pass method in Microsoft Entra

Persona can't create a pass until the method is on for the employee.

1.  In the Microsoft Entra admin center, go to **Entra ID > Authentication methods > Policies** and select **Temporary Access Pass**.
2.  Select **Enable**, and include a pilot group first, then everyone who may recover this way.
3.  Select **Configure** and set the default lifetime. Persona creates passes with the default lifetime.
4.  Leave **One-time** off unless you want every pass in your tenant to be one-time. Persona asks for one-time passes either way.
5.  Select **Save**.

### 3\. Configure the Persona inquiry template

Persona provides a ready-made inquiry template for this flow, with the workflows that look up the employee and create the pass. The wizard installs it in your workforce organization and applies your answers to it. Check the following before you publish.

1.  In the two **Find or Create Account** steps and the **Fetch Account Object** step, select your account type.
2.  In the two **Get Entra User** steps and the **Create temporary access pass** step, select the Microsoft Entra credential from Step 1.
3.  In the government ID verification template, check that the [Inquiry comparison](https://help.withpersona.com/articles/1qEE7AZz4NfDuCFqCBF7ZE/) check is on and fails the verification on a mismatch, so a pass is only created for the person named in Entra.
4.  Review the success and failure workflows. They email the employee when an inquiry completes or fails, and email your administrators when Persona can't find the employee in Entra after repeated attempts. Set the recipients and contact addresses to your own.
5.  Publish the verification templates, then the workflows, then the inquiry template.

### 4\. Start account recovery for an employee

Microsoft Entra doesn't send a locked-out employee to Persona on its own, so your helpdesk starts recovery.

1.  In the Persona Dashboard, go to **Inquiries** and create an inquiry from the installed template.
2.  Set the Reference ID to the employee's user principal name, or set the account type to **No Account**. Otherwise the inquiry creates a second account for the employee, and Persona can't recognize repeat attempts. If you leave both out, the employee enters their user principal name in the flow.
3.  Send the employee the inquiry link.

When the employee passes, the final screen shows their Temporary Access Pass with a link to sign in to Microsoft. The pass is only shown once. An employee who leaves the screen without copying it needs a new inquiry.

### 5\. Test the integration

1.  Send an inquiry to a test employee and complete it.
2.  Confirm that the final screen shows a Temporary Access Pass.
3.  Sign in at [Security info](https://mysignins.microsoft.com/security-info) as the test employee with the pass, and register a new authentication method.
4.  Test the failure path too. Fail an inquiry on purpose and confirm that no pass is created.

☝️

Microsoft Entra doesn't let an administrator create a Temporary Access Pass for their own account, so testing with the administrator who connected the integration fails. Test with a different user.

## Related resources

- [Microsoft Entra integration overview](https://help.withpersona.com/articles/76oPGnRkduS3sHbEpLNSku/)
- [Using Persona Workflows to manage Microsoft Entra users & profiles](https://help.withpersona.com/articles/6vHVa8KcEURyza3nk2v0RH/)
- [Microsoft Learn: Configure Temporary Access Pass to register passwordless authentication methods](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass)

## Plans Explained

### Microsoft Entra Integration by plan

|                             | Startup Program | Essential Plan | Growth Plan | Enterprise Plan |
| --------------------------- | --------------- | -------------- | ----------- | --------------- |
| Microsoft Entra Integration | Not Available   | Not Available  | Limited     | Available       |

[Learn more about pricing and plans](https://withpersona.com/pricing?utm_source=product&utm_medium=referral&utm_audience=a&utm_campaign=cm_gen_ds_hc-plan-table).

_Last updated on October 7, 2026._
