Concept and mechanism
An authentication-method policy determines who can use particular authentication forms. An authentication strength can limit combinations accepted for a resource or context. Meeting general MFA with password and SMS does not satisfy the built-in phishing-resistant strength. Evaluation occurs after initial authentication; entering a password does not demonstrate that resource access will be granted. Temporary Access Pass helps bootstrap method registration and recovery, with validity and one-time or multiple use according to configuration. An issued code needs appropriate policy, scope, and state. Once consumed in one-time mode, it must not be treated as a permanent credential. Retain identity verification and authority within support handling.
Guided application
Administrative recovery deserves its own design. Current guidance provides for at least two cloud-only emergency accounts with phishing-resistant methods and dependencies different from normal accounts. Protect credentials, monitor use, and regularly validate the path. Exclusions from restrictive policies aim to avoid emergency-access lockout; they do not mean abandoning mandatory MFA requirements. In a fictional organization, using the same federation and personal device for every administrator and emergency access retains a common failure. During containment, also distinguish a revocation request from effective access: tokens, CAE, and application-managed sessions influence termination. Reporting should say what was executed, what was observed, and which applications still need verification.
An emergency account requiring approval from a locked-out administrator can fail when most needed.
Common pitfalls
Two factors as every strength; TAP as permanent password; emergency as password-only; revoke as instantly ending all sessions.
Related topics: Tenant, scope, and objects · Hybrid identity and partners · Conditional Access and risk
Combine strong authentication with an independent, exercised recovery path.
Reference: Authentication strengths · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately