Time-based one-time password, an OATH standard. Each code is valid for a short window of 30 or 60 seconds and is produced either by an authenticator app (a software token) or by a physical hardware token.
Also called time-based one-time password.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains TOTP in context, with comparison tables and the common traps.
Terms in this definition
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- WINDOW
Returns rows from a sorted, optionally partitioned table, either at fixed positions (ABS) or relative to the current row (REL). Running totals plus moving averages are common uses.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Token
The unit of text an LLM works with, which may be a word, part of a word or punctuation. Billing, limits and context windows are all counted in these units.
- Physical
Describes the concrete, real-world parts that put a logical architecture into effect.
Related terms
- HOTP
A counter-based OATH method for one-time codes, as opposed to the time-based TOTP. Microsoft Entra ID supports only TOTP, not HOTP.
- MSCHAPv2
When the NPS extension is used and the RADIUS client talks to NPS with this challenge-response protocol, MFA is limited to push notifications and phone calls. Code-based (TOTP) methods require PAP.
- PAP
Password Authentication Protocol, a RADIUS password protocol which, when used between NPS and the RADIUS client, lets the NPS extension support all Microsoft Entra MFA methods, TOTP codes from OATH tokens or Authenticator included.