New: Account Recovery+ for Entra ID Read Now
When someone is locked out, an identity platform has to decide whether to trust a person it cannot see. When the built-in path runs out, that decision lands on a help desk agent taking a phone call under time pressure. That call is the opening attackers look for.
ATO Protect Account Recovery+ verifies the person against the authority that issued their government ID, then hands the recovery back to the identity platform you already run. Microsoft Entra ID is the first platform it supports.
Built-in self-service password reset works for users who registered enough methods in advance and still have them. When it cannot help, someone on a phone call has to decide who they are talking to, and that is the decision attackers go after.
Self-service password reset depends on authentication methods enrolled ahead of time. A day-one hire, a contractor, or anyone who skipped enrollment has nothing to prove with.
A user who registered one method, under a policy that now requires two, cannot complete the flow they were enrolled for.
When the fallback is a phone call, an agent working from a script has to judge whether the voice is genuine while the caller waits, and cloned audio clears that bar.
A lockout on a Saturday night waits for Monday morning, and so does the work that person was doing.
Verification runs in the mobile browser the user already has.
It works the first time someone needs it, including a user who never enrolled a method.
Users recover on their own, so nobody has to vouch for them over the phone.
Setup runs inside the tenant you already administer.
Recovery works at 2 a.m. on a Sunday, whether or not anyone is staffing the desk.
Trusona confirms the ID with the authority that issued it and screens the phone number for SIM swaps before anything is sent.
The user scans a government-issued ID in their mobile browser. Trusona checks it against the authority that issued it, and checks the phone number for SIM swaps and port-outs before trusting it. Trusona does not ask for a selfie or run a liveness check.
On a clean result, Trusona calls your identity platform through an app registration that lives in your own tenant, and asks it to issue a single-use pass. The pass goes to the verified number by SMS. Only the identity check happens outside your authentication system.
The user signs in with the pass and re-enrolls their authentication methods. Nobody had to judge a voice, because there was no voice on the line.
Each deployment is named for the platform it recovers into, which is why the first one is called ATO Protect Account Recovery+ for Entra ID.
Trusona confirms the person, then calls Microsoft Graph with your tenant's own app registration to mint a single-use Temporary Access Pass. The user signs in with it and sets up their sign-in methods again.
Explore Account Recovery+ for Entra ID →Account Recovery+ is a pattern rather than a one-off integration. Microsoft Entra ID is the platform it supports today. Tell us which one your users recover into.
Talk to us →Account Recovery+ needs no standing service account and no directory role.
Setup happens in your own tenant, and the exact roles depend on the platform. The Entra ID page names the roles its setup uses.
Microsoft Entra ID. It is live, and its own page covers the setup, the two Graph permissions, and the administrator roles involved. If you run a different platform, tell us which one and we will talk through what that would take.
No. Account Recovery+ is self-service. The user proves who they are with a government-issued ID and receives the pass directly, at any hour, so no agent or manager has to decide whether the request is genuine.
No. Verification runs in the user's mobile browser against authoritative records, so it works the first time a user ever needs it, including for someone who never finished registering authentication methods.
It is included free in the ATO Protect Suite. For anything about pricing, speak with our team.
The number is checked before anything is sent to it. ATO Protect runs SIM swap and man-in-the-middle detection across multiple international phone networks as part of the verification, and the pass can only be used once. A number that moved to a new device recently is a reason to stop.
No, and it is not meant to. A built-in reset flow handles the users it was designed for, and the two run side by side. Account Recovery+ is built for the users that flow sends to an administrator.
No. Generative AI can defeat those methods, so Trusona verifies the document against the issuing authority instead. This is a deliberate position rather than a gap.
See a recovery run end to end in a demo.
Microsoft, Microsoft Entra ID and Temporary Access Pass are trademarks of Microsoft Corporation. Trusona is not affiliated with or endorsed by Microsoft.