Description:

This posture check verifies that Temporary Access Pass settings are enabled, using the Default settings.

Why:

Verifies that Temporary Access Pass settings are enabled, using the Default settings. A Temporary Access Pass is a time-limited passcode that can be configured for single use or multiple. Users can sign in with a Temporary Access Pass to onboard other authentication methods including passwordless methods such as Microsoft Authenticator, FIDO2 or Windows Hello for Business. A Temporary Access Pass also makes recovery easier when a user has lost or forgotten their strong authentication factor like a FIDO2 security key or Microsoft Authenticator app, but needs to sign in to register new strong authentication methods.

Status detail shown in Augmentt: You have N out of M settings applied.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Identity

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.AA-02

  • HIPAA Security Rule — 164.312(d)

  • CMMC Level 2 — IA.L2-3.5.2

Microsoft documentation:


_KB status: already published as "Temporary Access Pass" — update the existing step in place._

_Source: Augmentt native check. Check ID temporaryaccesspass (module 31)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft Entra ID · Identity · M365 Basic · NIST CSF 2.0 · HIPAA · CMMC Level 2