Reset 2FA
Removes authentication methods and, if needed, issues a Temporary Access Pass (TAP) for re-enrolment.
Required permission :2FA
Remove a single method
Removes a single authentication method (phone, app, security key…) without touching the others.
Where to find it : User profile → “2FA” panel → list of registered methods
Fields to fill in
No field to fill in — a single confirmation button is enough.
Checkboxes and options
No checkbox for this action.
Good to know
- A method type not recognised by Microsoft Graph does not offer this button; remove it from the Entra portal instead.
Reset every method
Removes every registered 2FA method and can issue a Temporary Access Pass so the user can sign back in and re-register their methods.
Where to find it : User profile → “2FA” panel → “Reset all”
Fields to fill in
| Field | Description | Example | Required |
|---|---|---|---|
| Valid for (minutes) | How long the Temporary Access Pass stays valid, from 10 to 43,200 minutes (30 days). | 60 | Yes, if the Temporary Access Pass is enabled |
Checkboxes and options
| Option | Description |
|---|---|
| Generate a Temporary Access Pass (TAP) | Issues a code the user enters instead of a password to sign back in. |
| Single use | The code only works once. Unchecked, it stays valid until its lifetime expires. |
Good to know
- The Temporary Access Pass is shown only once: note it down before closing the window.
- Also requires the Authentication Administrator directory role assigned to the application on this tenant.
- If a method cannot be removed (unrecognised type), it is reported after the operation and the reset stays incomplete for that user.
Take back control of your clients’ tenants
Set up EasyTenant in minutes and handle your day-to-day requests from a single interface.
The full app, on sample data. No account, no card.