New: Account Recovery+ for Entra ID Read Now
Trusona has a new account recovery option for Microsoft Entra ID that verifies the True Persona. It is a self-service user flow that saves calls to the IT help desk.
ATO Protect Account Recovery+ runs a battery of checks to foil GenAI deepfakes, including a verification of a government-issued ID against the authority that issued it. It then sends a single-use Temporary Access Pass (TAP). The user signs in with it and sets up their sign-in methods again.
Verification runs in the mobile browser the user already has.
It works the first time someone needs it, including a user who never enrolled a method.
Users recover on their own, so nobody has to vouch for them over the phone.
Setup runs in your own Entra ID tenant.
Recovery works at 2 a.m. on a Sunday, whether or not anyone is staffing the desk.
Trusona verifies the ID with the issuing authority and screens the phone number for SIM swaps before it sends a TAP.
The user scans a government-issued ID in their mobile browser. Trusona checks it against the authority that issued it, and checks the phone number for SIM swaps and port-outs before trusting it. Trusona does not ask for a selfie or run a liveness check.
On a clean result, Trusona calls Microsoft Graph with your tenant's own app registration and mints a single-use Temporary Access Pass. It goes to the verified number by SMS.
The user signs in to Entra ID with the TAP and completes the recovery process. Nobody had to judge a voice, because there was no voice on the line.
The solution briefing puts Account Recovery+ on a single page: the six differentiators and how a recovery works.
PDF, one page, 1.4 MB
Self-service password reset in Entra ID works for users who registered recovery methods and still have access to them. For everyone else, its answer is to contact the help desk.
Reset depends on authentication methods registered in advance. Without them, the user is told to contact the helpdesk.
A user registered for one method, under a policy requiring two, is unable to reset.
A lost or stolen phone takes the methods registered on it.
In a hybrid tenant without password writeback, a user whose password is managed on-premises is told to contact the help desk
Read more about where Entra self-service password reset stops
Account Recovery+ needs no standing service account and no directory role.
No. Account Recovery+ is self-service. The user proves who they are with a government-issued ID and receives the TAP directly, at any hour, so no agent or manager has to decide whether the request is genuine.
No. Verification runs in the user's mobile browser against authoritative records, so it works the first time a user ever needs it, including for someone who never finished registering authentication methods in Entra ID.
It is included free in the ATO Protect Suite. For anything about pricing, speak with our team.
No. The integration runs on an app-only access token from an app registration in your own tenant, carrying two narrowly scoped Microsoft Graph permissions. The application is assigned no Entra directory role at all, and Trusona holds no service account and no directory password. A Privileged Role Administrator or Global Administrator grants admin consent once during setup, and never again at run time.
Application Administrator to create the app registration, Privileged Role Administrator or Global Administrator to grant admin consent for the two Microsoft Graph permissions, and Authentication Policy Administrator to enable the Temporary Access Pass method.
The number is checked before anything is sent to it. ATO Protect runs SIM swap and man-in-the-middle detection across multiple international phone networks as part of the verification, and the TAP can only be used once. A number that moved to a new device recently is a reason to stop.
No, and it is not meant to. Entra SSPR handles the users it was designed for, and the two run side by side. Account Recovery+ is built for the users Microsoft's reset flow sends to an administrator.
No. Generative AI can defeat those methods, so Trusona verifies the document against the issuing authority instead. This is a deliberate position rather than a gap.
See the full recovery flow in a demo.
Microsoft Entra ID behavior described on this page is drawn from Microsoft's own documentation, retrieved September 15, 2026: Self-service password reset deep dive and Configure a Temporary Access Pass. Microsoft, Microsoft Entra ID and Temporary Access Pass are trademarks of Microsoft Corporation. Trusona is not affiliated with or endorsed by Microsoft.