Forum Discussion

aguenthart's avatar
aguenthart
Copper Contributor
Dec 26, 2024
Solved

Intune - Phishing-Resistant MFA

Good Afternoon, So sorry but I'm quite novice. I am trying to merge all Intune users to phishing-resistant MFA (PR-MFA) only (excluding break-the-glass users/admins). On Entra, I do this by disablin...
  • tschlappinger's avatar
    Dec 30, 2024

    The keyword for this is Temporary Access Pass. You create the policy under:
    Entra IDProtectionAuthentication MethodsTemporary Access Pass.

    For a new user, go to:
    Entra IDUsersAll Users, select the "new" user, and click on Authentication Methods + Add Authentication Method, then choose Temporary Access Pass. Share this pass with the user.

    Using a Temporary Access Pass

    Typically, a user registers authentication methods during their first sign-in. The Temporary Access Pass is perfect for setting up or updating multifactor, passwordless, or phishing-resistant authentication without requiring additional security prompts.

    Registering Authentication Methods

    Authentication methods can be registered at https://aka.ms/mysecurityinfo. Users can also update existing authentication methods here.
    After a successful sign-in, the user can now register or update passwordless authentication methods, such as FIDO2 security keys or the Microsoft Authenticator app.


    https://techcommunity.microsoft.com/blog/identity/secure-authentication-method-provisioning-with-temporary-access-pass/3290631

Resources