Home›Identity Security›Authentication & MFA
Section
Authentication & MFA
Auth methods, registration gaps, and the road to passwordless.
Temporary Access Pass is a loaded gun: using it without shooting yourself
A TAP isn't an MFA bypass — it's a strong credential that bootstraps persistent access, which is exactly why it's dangerous. The real risks, and the policy, scoping, and Conditional Access controls that keep it from becoming your weakest link.
Read →The password nobody can set: Entra Password Protection, end to end
How on-prem Entra Password Protection blocks weak passwords — proxy servers, the DC agent, SCP discovery, SYSVOL caching — plus the scoring algorithm that decides accept or reject, with worked examples.
Read →Going passwordless on Windows, end to end
Authenticator phone sign-in, the Windows Passwordless Experience policy, hiding the password UI with DisableCredentialProviders, and a TPM-backed PIN fallback — without locking anyone out.
Read →SSPR without locking everyone out
Self-service password reset can lock out a whole tenant if you enable it against raw objects. The pre-flight checks that matter, and what breaks when you skip them.
Read →