Skip to content

Reset 2FA

Removes authentication methods and, if needed, issues a Temporary Access Pass (TAP) for re-enrolment.

Required permission :2FA

Remove a single method

Removes a single authentication method (phone, app, security key…) without touching the others.

Where to find it : User profile → “2FA” panel → list of registered methods

Fields to fill in

No field to fill in — a single confirmation button is enough.

Checkboxes and options

No checkbox for this action.

Good to know

  • A method type not recognised by Microsoft Graph does not offer this button; remove it from the Entra portal instead.

Reset every method

Removes every registered 2FA method and can issue a Temporary Access Pass so the user can sign back in and re-register their methods.

Where to find it : User profile → “2FA” panel → “Reset all”

Fields to fill in

FieldDescriptionExampleRequired
Valid for (minutes)How long the Temporary Access Pass stays valid, from 10 to 43,200 minutes (30 days).60Yes, if the Temporary Access Pass is enabled

Checkboxes and options

OptionDescription
Generate a Temporary Access Pass (TAP)Issues a code the user enters instead of a password to sign back in.
Single useThe code only works once. Unchecked, it stays valid until its lifetime expires.

Good to know

  • The Temporary Access Pass is shown only once: note it down before closing the window.
  • Also requires the Authentication Administrator directory role assigned to the application on this tenant.
  • If a method cannot be removed (unrecognised type), it is reported after the operation and the reset stays incomplete for that user.

Take back control of your clients’ tenants

Set up EasyTenant in minutes and handle your day-to-day requests from a single interface.

The full app, on sample data. No account, no card.