What a TAP is for, its lifetime and length settings, and which role can create one for which users.
From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)
A Temporary Access Pass (TAP) is a time-limited passcode that lets a user sign in and register a passwordless method, or recover after losing a strong method. It counts as both first factor and MFA.
| TAP setting | Default | Allowed range |
|---|---|---|
| Minimum lifetime | 1 hour | 10 minutes - 43,200 minutes (30 days) |
| Maximum lifetime | 8 hours | 10 minutes - 30 days |
| Default lifetime | 1 hour | 10 minutes - 30 days |
| One-time use | False | True/False (True forces all passes to one-time) |
| Length | 8 characters | 8-48 characters |
Who does what:
| Task | Least-privileged role |
|---|---|
| Enable the TAP method and scope groups | Authentication Policy Administrator |
| Create, view or delete a TAP for members (not themselves) | Authentication Administrator |
| Create, view or delete a TAP for admins and members | Privileged Authentication Administrator |
| View TAP details without the code | Global Reader |
Key behaviour:
Connect-MgGraph -Scopes "UserAuthenticationMethod.ReadWrite.All"
$properties = @{ isUsableOnce = $true; startDateTime = '2026-11-02 08:00:00' }
New-MgUserAuthenticationTemporaryAccessPassMethod -UserId user1@example.com `
-BodyParameter ($properties | ConvertTo-Json)Common trap: Issuing a TAP and wondering why the user never sees the prompt - creating a TAP doesn’t put the user in scope. The TAP method must be enabled in the Authentication methods policy for a group that contains the user, and a one-time TAP mustn’t already have been used.
This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-300 terms in the glossary · All SC-300 study notes
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
The difference between the two risk types, real-time versus offline detections, and which detections need P2.
How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.
Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.