Skip to content
Help Center

Issue Microsoft Entra Temporary Access Passes with Persona

View Markdown Contact support Contact support 5 min read
On this page

About Microsoft Entra Temporary Access Pass

Microsoft Entra supports a Temporary Access Pass (TAP). A TAP is a time-limited passcode that lets a user sign in when they can’t use their usual authentication methods, for example when they lose their phone or forget their security key. Once signed in, the user can register new methods. An administrator creates the pass and hands it to the user, so your helpdesk has to confirm who is asking for it first.

With Persona, the employee proves who they are with a government ID and selfie verification. Persona compares the name on the ID with their Entra profile, and only then creates the Temporary Access Pass and shows it to the employee. This helps protect account recovery against social engineering, deepfakes, and account takeover, and your helpdesk never handles the pass.

How it works

  1. Your helpdesk sends the employee a Persona verification link.
  2. Persona looks up the employee in Microsoft Entra by their user principal name (UPN).
  3. The employee completes a government ID and selfie verification. Persona compares the government ID with the employee’s Entra profile.
  4. If the verification passes, Persona creates a Temporary Access Pass in Microsoft Entra and shows it on the final screen.
  5. The employee signs in to Microsoft with the pass and registers a new authentication method.

Use a Persona organization dedicated to your workforce, separate from any organization that verifies your customers, so employee and customer data stay apart. Ask your Persona contact if you don’t have one yet.

Microsoft Entra Configuration Guide

Follow the steps below to issue Microsoft Entra Temporary Access Passes with Persona. The Microsoft Entra Temporary Access Pass wizard in the Persona Dashboard walks you through the same steps and checks your setup as you go.

1. Configure Persona Marketplace Integration for Employee Data

Context

Persona requires access to your Microsoft Entra tenant through Microsoft Graph, both to look up the employee and to create their Temporary Access Pass.

In order to ensure the employee being verified matches the Entra account being recovered, Persona compares the values extracted from the employee’s government ID with the given name and surname stored in their Entra user profile.

Please ensure that the names that are stored in Entra are employee legal names, rather than preferred names or nicknames.

Connect Microsoft Entra

  1. Follow Connect Microsoft Entra ID to your Persona account to add a credential under Integrations > Marketplace > Microsoft Entra ID in the Persona Dashboard.
  2. Connect with an Entra administrator who can create a Temporary Access Pass for the employees in scope. An Authentication Administrator can create passes for members, and a Privileged Authentication Administrator can also create them for administrators. Persona creates each pass as this administrator, and Entra won’t create one for that administrator’s own account.
  3. Use Test to check the connection before continuing.

2. Turn on the Temporary Access Pass method in Microsoft Entra

Persona can’t create a pass until the method is on for the employee.

  1. In the Microsoft Entra admin center, go to Entra ID > Authentication methods > Policies and select Temporary Access Pass.
  2. Select Enable, and include a pilot group first, then everyone who may recover this way.
  3. Select Configure and set the default lifetime. Persona creates passes with the default lifetime.
  4. Leave One-time off unless you want every pass in your tenant to be one-time. Persona asks for one-time passes either way.
  5. Select Save.

3. Configure the Persona inquiry template

Persona provides a ready-made inquiry template for this flow, with the workflows that look up the employee and create the pass. The wizard installs it in your workforce organization and applies your answers to it. Check the following before you publish.

  1. In the two Find or Create Account steps and the Fetch Account Object step, select your account type.
  2. In the two Get Entra User steps and the Create temporary access pass step, select the Microsoft Entra credential from Step 1.
  3. In the government ID verification template, check that the Inquiry comparison check is on and fails the verification on a mismatch, so a pass is only created for the person named in Entra.
  4. Review the success and failure workflows. They email the employee when an inquiry completes or fails, and email your administrators when Persona can’t find the employee in Entra after repeated attempts. Set the recipients and contact addresses to your own.
  5. Publish the verification templates, then the workflows, then the inquiry template.

4. Start account recovery for an employee

Microsoft Entra doesn’t send a locked-out employee to Persona on its own, so your helpdesk starts recovery.

  1. In the Persona Dashboard, go to Inquiries and create an inquiry from the installed template.
  2. Set the Reference ID to the employee’s user principal name, or set the account type to No Account. Otherwise the inquiry creates a second account for the employee, and Persona can’t recognize repeat attempts. If you leave both out, the employee enters their user principal name in the flow.
  3. Send the employee the inquiry link.

When the employee passes, the final screen shows their Temporary Access Pass with a link to sign in to Microsoft. The pass is only shown once. An employee who leaves the screen without copying it needs a new inquiry.

5. Test the integration

  1. Send an inquiry to a test employee and complete it.
  2. Confirm that the final screen shows a Temporary Access Pass.
  3. Sign in at Security info as the test employee with the pass, and register a new authentication method.
  4. Test the failure path too. Fail an inquiry on purpose and confirm that no pass is created.

Microsoft Entra doesn’t let an administrator create a Temporary Access Pass for their own account, so testing with the administrator who connected the integration fails. Test with a different user.

Plans Explained

Microsoft Entra Integration by plan

Startup ProgramEssential PlanGrowth PlanEnterprise Plan
Microsoft Entra IntegrationNot AvailableNot AvailableLimitedAvailable

Learn more about pricing and plans.

Last updated on .

Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.