New: Account Recovery+ for Entra ID Read Now

ATO Protect Account Recovery+

Account recovery without a help desk call.

When someone is locked out, an identity platform has to decide whether to trust a person it cannot see. When the built-in path runs out, that decision lands on a help desk agent taking a phone call under time pressure. That call is the opening attackers look for.

ATO Protect Account Recovery+ verifies the person against the authority that issued their government ID, then hands the recovery back to the identity platform you already run. Microsoft Entra ID is the first platform it supports.

Where locked-out users get stuck

Built-in self-service password reset works for users who registered enough methods in advance and still have them. When it cannot help, someone on a phone call has to decide who they are talking to, and that is the decision attackers go after.

  1. They never finished registering

    Self-service password reset depends on authentication methods enrolled ahead of time. A day-one hire, a contractor, or anyone who skipped enrollment has nothing to prove with.

  2. The policy changed underneath them

    A user who registered one method, under a policy that now requires two, cannot complete the flow they were enrolled for.

  3. An agent has to judge a voice

    When the fallback is a phone call, an agent working from a script has to judge whether the voice is genuine while the caller waits, and cloned audio clears that bar.

  4. The desk is closed

    A lockout on a Saturday night waits for Monday morning, and so does the work that person was doing.

Account Recovery+ at a glance

  • No app to download

    Verification runs in the mobile browser the user already has.

  • No user pre-registration

    It works the first time someone needs it, including a user who never enrolled a method.

  • No call to the help desk / manager

    Users recover on their own, so nobody has to vouch for them over the phone.

  • Included FREE in ATO Protect

    Setup runs inside the tenant you already administer.

  • Available 24x7

    Recovery works at 2 a.m. on a Sunday, whether or not anyone is staffing the desk.

  • Secured by Trusona

    Trusona confirms the ID with the authority that issued it and screens the phone number for SIM swaps before anything is sent.

How it works

  1. 1

    Verify the person

    The user scans a government-issued ID in their mobile browser. Trusona checks it against the authority that issued it, and checks the phone number for SIM swaps and port-outs before trusting it. Trusona does not ask for a selfie or run a liveness check.

  2. 2

    Ask your platform for a pass

    On a clean result, Trusona calls your identity platform through an app registration that lives in your own tenant, and asks it to issue a single-use pass. The pass goes to the verified number by SMS. Only the identity check happens outside your authentication system.

  3. 3

    Sign in and re-enroll

    The user signs in with the pass and re-enrolls their authentication methods. Nobody had to judge a voice, because there was no voice on the line.

Identity platforms

Each deployment is named for the platform it recovers into, which is why the first one is called ATO Protect Account Recovery+ for Entra ID.

  • Available now

    Microsoft Entra ID

    Trusona confirms the person, then calls Microsoft Graph with your tenant's own app registration to mint a single-use Temporary Access Pass. The user signs in with it and sets up their sign-in methods again.

    Explore Account Recovery+ for Entra ID →
  • Other platforms

    Running something else?

    Account Recovery+ is a pattern rather than a one-off integration. Microsoft Entra ID is the platform it supports today. Tell us which one your users recover into.

    Talk to us →

What your identity team will ask about

Account Recovery+ needs no standing service account and no directory role.

What it uses

  • An app registration that lives in your own tenant
  • Narrowly scoped API permissions, consented by you
  • Short-lived access tokens, re-acquired when they expire
  • Client secret rotation that takes effect on the next token acquisition

What it never needs

  • A directory role assigned to the application
  • A service account with a standing password
  • A directory password held by Trusona
  • An administrator signing in at run time
  • An app on the user's phone
  • User pre-registration
  • PII retained after the session

Setup happens in your own tenant, and the exact roles depend on the platform. The Entra ID page names the roles its setup uses.

Questions buyers ask

Which identity platforms does Account Recovery+ support today?

Microsoft Entra ID. It is live, and its own page covers the setup, the two Graph permissions, and the administrator roles involved. If you run a different platform, tell us which one and we will talk through what that would take.

Do users still need to call the help desk?

No. Account Recovery+ is self-service. The user proves who they are with a government-issued ID and receives the pass directly, at any hour, so no agent or manager has to decide whether the request is genuine.

Does the user need an app or a pre-registered identity?

No. Verification runs in the user's mobile browser against authoritative records, so it works the first time a user ever needs it, including for someone who never finished registering authentication methods.

How is Account Recovery+ licensed?

It is included free in the ATO Protect Suite. For anything about pricing, speak with our team.

Is SMS delivery safe against SIM swapping?

The number is checked before anything is sent to it. ATO Protect runs SIM swap and man-in-the-middle detection across multiple international phone networks as part of the verification, and the pass can only be used once. A number that moved to a new device recently is a reason to stop.

Does this replace the self-service password reset we already have?

No, and it is not meant to. A built-in reset flow handles the users it was designed for, and the two run side by side. Account Recovery+ is built for the users that flow sends to an administrator.

Do you check a selfie or run liveness detection?

No. Generative AI can defeat those methods, so Trusona verifies the document against the issuing authority instead. This is a deliberate position rather than a gap.

Give locked-out users a way back in

See a recovery run end to end in a demo.

Microsoft, Microsoft Entra ID and Temporary Access Pass are trademarks of Microsoft Corporation. Trusona is not affiliated with or endorsed by Microsoft.

trusona icon
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.