{"id":75,"date":"2022-12-26T08:05:00","date_gmt":"2022-12-26T00:05:00","guid":{"rendered":"https:\/\/www.ruianding.com\/blog\/?p=75"},"modified":"2025-03-18T17:43:30","modified_gmt":"2025-03-18T09:43:30","slug":"enable-web-sign-in-with-temporary-access-pass","status":"publish","type":"post","link":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/","title":{"rendered":"Enable Web Sign-in with Temporary Access Pass"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"overview\"><strong>Overview<\/strong><\/h2>\n\n\n\n<p>This post will share how to implement Web Sign-in Feature, and this feature will allow the user sign-in Windows with the TAP (Temporary Access Pass).<\/p>\n\n\n\n<p>As the reminder, the Web Sign-in feature used to be the feature that can support 3rd party federation sign-in and MFA. For example, AAD Joined machine only supports 3rd party IDP with WS-TRUST protocol, and 3rd party such as Google IDP will not able to login Windows due to its federation protocol is SAML2. However, with Web Sign-in feature, user would be able to sign-in since an embedded browser looking window will pop up. And it is different from the normal Windows Sign-in, and the limitation due to the federation protocol will no longer exist.<\/p>\n\n\n\n<p>Besides, due to Windows Sign-in is considered as non-interactive, and the interactive MFA will not be supported. The web sign-in can also mitigate this limitation, which allows user to do MFA in the embedded browser window.<\/p>\n\n\n\n<p>However, the bad news is Web Sign-in is not a public released feature and Microsoft Product team has already disabled this private preview feature. Currently, only Temporary Access Pass could be used in order to sign-in windows. Refering below Microsoft Documentation:<br><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/whats-new\/whats-new-windows-10-version-1809#web-sign-in-to-windows-10\">What&#8217;s new in Windows 10, version 1809 &#8211; What&#8217;s new in Windows | Microsoft Learn<\/a>\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"751\" height=\"173\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png\" alt=\"\" class=\"wp-image-2657\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png 751w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-300x69.png 300w\" sizes=\"auto, (max-width: 751px) 100vw, 751px\" \/><\/figure>\n\n\n\n<p>Nevertheless, we still can use the Web Sign-in feature with TAP. The down below sections will provide the instructions to configure the Web Sign-in and TAP.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"1-what-is-temporary-access-pass\"><strong>1. What is Temporary Access Pass?<\/strong><\/h2>\n\n\n\n<p>Please refer below Microsoft Documentation for the introduction to TAP.<br><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/authentication\/howto-authentication-temporary-access-pass\">Configure a Temporary Access Pass in Azure AD to register Passwordless authentication methods &#8211; Microsoft Entra | Microsoft Learn<\/a><\/p>\n\n\n\n<p><strong>Here&#8217;s the definition for TAP:<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>A&nbsp;<strong>Temporary Access Pass<\/strong>&nbsp;is a time-limited passcode that can be configured for multi or single use to allow users to onboard other authentication methods including passwordless methods such as Microsoft Authenticator, FIDO2 or Windows Hello for Business.<\/p>\n<\/blockquote>\n\n\n\n<p>TAP could be considered as a strong authentication method such as passwordless. In other words, once the user authenticated via TAP, both primary and secondary authentication will be satisfied. This post will not go into too much detail about other TAP application scenarios. Below is one of the implemation of the TAP. Secure authentication method provisioning with Temporary Access Pass &#8211; Microsoft Tech Community<\/p>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"2-instructions-of-configuring-web-sign-in\"><strong>2. Instructions of Configuring Web Sign-in<\/strong><\/h2>\n\n\n\n<p>1.&nbsp;Sign-in to the Microsoft Endpoint Manager admin center (Intune Portal).<\/p>\n\n\n\n<p>2.&nbsp;Select&nbsp;<strong>Devices<\/strong>&nbsp;&gt;&nbsp;<strong>Configuration profiles<\/strong>&nbsp;&gt;&nbsp;<strong>Create profile<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"513\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-1-1024x513.png\" alt=\"\" class=\"wp-image-2658\" style=\"width:721px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-1-1024x513.png 1024w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-1-300x150.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-1-768x385.png 768w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-1.png 1380w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>3.&nbsp;Choose&nbsp;<strong>Windows 10 and later<\/strong>&nbsp;as the Platform;&nbsp;<strong>Templates<\/strong>&nbsp;as the Profile type;&nbsp;<strong>Custom<\/strong>&nbsp;as the template name. &gt; Click&nbsp;<strong>Create<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"566\" height=\"724\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-2.png\" alt=\"\" class=\"wp-image-2660\" style=\"width:288px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-2.png 566w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-2-235x300.png 235w\" sizes=\"auto, (max-width: 566px) 100vw, 566px\" \/><\/figure>\n\n\n\n<p>4.&nbsp;Give the policy a&nbsp;<strong>Name<\/strong>&nbsp;&gt; Click&nbsp;<strong>Next<\/strong><\/p>\n\n\n\n<p>5.&nbsp;Add the custom rules as below under&nbsp;<strong>Configuration settings<\/strong>, add the&nbsp;<strong>OMA-URI Settings<\/strong>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Name: Web Sign In\nOMA-URI: .\/Device\/Vendor\/MSFT\/Policy\/Config\/Authentication\/EnableWebSignIn\nData Type: Integer\nValue: 1<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"781\" height=\"393\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-3.png\" alt=\"\" class=\"wp-image-2661\" style=\"width:398px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-3.png 781w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-3-300x151.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-3-768x386.png 768w\" sizes=\"auto, (max-width: 781px) 100vw, 781px\" \/><\/figure>\n\n\n\n<p>6.&nbsp;Assign this policy to the group who has enrolled their devices with Intune. Create the policy, then wait for the policy to apply to the devices.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"528\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-4-1024x528.png\" alt=\"\" class=\"wp-image-2662\" style=\"width:596px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-4-1024x528.png 1024w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-4-300x155.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-4-768x396.png 768w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-4.png 1168w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"3-instructions-of-setting-up-temporary-access-pass\"><strong>3. Instructions of setting up Temporary Access Pass<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"31-enable-temporary-access-pass-for-your-aad-tenant\"><strong>3.1 Enable Temporary Access Pass for your AAD tenant<\/strong><\/h3>\n\n\n\n<p>1.\u00a0Sign-in to the\u00a0<strong>Azure Active Directory<\/strong>. <\/p>\n\n\n\n<p>2.\u00a0Select\u00a0<strong>Security<\/strong>\u00a0Blade >\u00a0<strong>Authentication methods<\/strong>\u00a0> Enable the users\/groups that you wants to apply the TAP:\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"561\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-5-1024x561.png\" alt=\"\" class=\"wp-image-2663\" style=\"width:689px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-5-1024x561.png 1024w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-5-300x164.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-5-768x421.png 768w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-5.png 1226w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"32-create-the-temporary-access-pass\"><strong>3.2 Create the Temporary Access Pass<\/strong><\/h3>\n\n\n\n<p>1.\u00a0Go to\u00a0<strong>Users<\/strong>\u00a0Blade > Select the targeted user > Click\u00a0<strong>Authentication methods<\/strong>\u00a0>\u00a0<strong>Add authentication method<\/strong>\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1011\" height=\"608\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-6.png\" alt=\"\" class=\"wp-image-2664\" style=\"width:422px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-6.png 1011w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-6-300x180.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-6-768x462.png 768w\" sizes=\"auto, (max-width: 1011px) 100vw, 1011px\" \/><\/figure>\n\n\n\n<p>2.\u00a0Choose\u00a0<strong>Temporary Access Pass<\/strong>\u00a0as the method, customize the settings that you want > Then\u00a0<strong>Add<\/strong>\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"575\" height=\"388\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-7.png\" alt=\"\" class=\"wp-image-2665\" style=\"width:326px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-7.png 575w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-7-300x202.png 300w\" sizes=\"auto, (max-width: 575px) 100vw, 575px\" \/><\/figure>\n\n\n\n<p>3.\u00a0You will be able to see the TAP after you click Add. <\/p>\n\n\n\n<p>4.\u00a0<strong>Copy &amp; Save<\/strong>\u00a0the Pass for further use.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"567\" height=\"516\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-8.png\" alt=\"\" class=\"wp-image-2666\" style=\"width:340px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-8.png 567w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-8-300x273.png 300w\" sizes=\"auto, (max-width: 567px) 100vw, 567px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"4test-the-windows-web-sign-in-with-your-tap\"><strong>4.Test the Windows Web Sign-in with your TAP<\/strong><\/h2>\n\n\n\n<p>1.\u00a0Click\u00a0<strong>Sign-in Options<\/strong>\u00a0> Click\u00a0<strong>Web Sign-in Icon<\/strong>\u00a0> Click\u00a0<strong>Sign-in<\/strong>\u00a0After\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"447\" height=\"517\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-9.png\" alt=\"\" class=\"wp-image-2667\" style=\"width:253px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-9.png 447w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-9-259x300.png 259w\" sizes=\"auto, (max-width: 447px) 100vw, 447px\" \/><\/figure>\n\n\n\n<p>2.\u00a0Enter your Azure AD UPN > Enter the TAP we created on previous steps.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"686\" height=\"665\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-10.png\" alt=\"\" class=\"wp-image-2668\" style=\"width:337px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-10.png 686w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-10-300x291.png 300w\" sizes=\"auto, (max-width: 686px) 100vw, 686px\" \/><\/figure>\n\n\n\n<p>3.\u00a0Congratulations, you are signed in.\u00a0<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"897\" height=\"621\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-11.png\" alt=\"\" class=\"wp-image-2669\" style=\"width:426px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-11.png 897w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-11-300x208.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-11-768x532.png 768w\" sizes=\"auto, (max-width: 897px) 100vw, 897px\" \/><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"5deep-dive\"><strong>5.Deep Dive<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"51-does-the-prt-contain-mfa-claim-with-tap-web-sign-in\"><strong>5.1 Does the PRT contain MFA claim with TAP web sign-in?<\/strong><\/h3>\n\n\n\n<p>As can be seen below, the once we sign-in with the TAP, our credential type is NGC (Next Generation Credential), which equivalent to WHfB sign-in. And as tested, the PRT contained the MFA claim and user will not be challenged to do MFA anymore.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"902\" height=\"286\" src=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-12.png\" alt=\"\" class=\"wp-image-2670\" style=\"width:742px;height:auto\" srcset=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-12.png 902w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-12-300x95.png 300w, https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image-12-768x244.png 768w\" sizes=\"auto, (max-width: 902px) 100vw, 902px\" \/><\/figure>\n\n\n\n<p>As mentioned before, once the user authenticated via TAP, both primary and secondary authentication will be satisfied. In this case, we can conclude more that this also applies to Windows Web sign-in using TAP.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"52-can-hybrid-azure-ad-joined-device-use-the-tap-to-sign-in\"><strong>5.2 Can Hybrid Azure AD Joined device use the TAP to sign-in?<\/strong><\/h3>\n\n\n\n<p>The conclusion is that TAP is not supported for Hybrid Azure AD joined device.<\/p>\n\n\n\n<p>For HAADJ device, after Intune policy applied to the device, we could also see the Web Sign-in option. However, after the sign-in finished. User will not able to login to windows and it will switch back to the sign-in options UI.<\/p>\n\n\n\n<p>I suspect that we have done the authentication to AAD via TAP, but we are missing some mechanism with authentication to on-prem Domain Controller\/Kerberos provider since the primary authority for authentication of Hybrid Azure AD join device would still be on-prem DCs.<\/p>\n\n\n\n<p>Like WHfB, it offers 3 trust types in order to connect authentication between the Cloud AAD and on-prem AD.<\/p>\n\n\n\n<p>All in all, based on my testing and understanding of device registration, TAP Web sign-in now seems to be unsuitable for hybrid-joined devices because it doesn&#8217;t have the same mechanism as WHfB or FIDO2 key which look for on-prem KDC authentication.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview This post will share how to implement Web Sign-in Feature, and this feature will allow the user sign-in Windows with the TAP (Temporary Access Pass). As the reminder, the Web Sign-in feature used to be the feature that can support 3rd party federation sign-in and MFA. For example, AAD Joined machine only supports 3rd [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[10],"tags":[6,20,21],"class_list":["post-75","post","type-post","status-publish","format-standard","hentry","category-tutorial","tag-drs","tag-ngc","tag-whfb"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Enable Web Sign-in with Temporary Access Pass - \u6781\u7b80IT\uff5cSimpleIT<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enable Web Sign-in with Temporary Access Pass - \u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"og:description\" content=\"Overview This post will share how to implement Web Sign-in Feature, and this feature will allow the user sign-in Windows with the TAP (Temporary Access Pass). As the reminder, the Web Sign-in feature used to be the feature that can support 3rd party federation sign-in and MFA. For example, AAD Joined machine only supports 3rd [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\" \/>\n<meta property=\"og:site_name\" content=\"\u6781\u7b80IT\uff5cSimpleIT\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-26T00:05:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-18T09:43:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png\" \/>\n\t<meta property=\"og:image:width\" content=\"751\" \/>\n\t<meta property=\"og:image:height\" content=\"173\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ruian Ding\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ruian Ding\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\"},\"author\":{\"name\":\"Ruian Ding\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"headline\":\"Enable Web Sign-in with Temporary Access Pass\",\"datePublished\":\"2022-12-26T00:05:00+00:00\",\"dateModified\":\"2025-03-18T09:43:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\"},\"wordCount\":889,\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"image\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png\",\"keywords\":[\"DRS\",\"NGC\",\"WHFB\"],\"articleSection\":[\"Tutorial\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\",\"name\":\"Enable Web Sign-in with Temporary Access Pass - \u6781\u7b80IT\uff5cSimpleIT\",\"isPartOf\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png\",\"datePublished\":\"2022-12-26T00:05:00+00:00\",\"dateModified\":\"2025-03-18T09:43:30+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png\",\"width\":751,\"height\":173},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.ruianding.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Enable Web Sign-in with Temporary Access Pass\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#website\",\"url\":\"https:\/\/www.ruianding.com\/blog\/\",\"name\":\"Ruian's Tech Troubleshooting Toolbox\",\"description\":\"Debug the World.\",\"publisher\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\"},\"alternateName\":\"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b\",\"name\":\"Ruian Ding\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"contentUrl\":\"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png\",\"width\":284,\"height\":284,\"caption\":\"Ruian Ding\"},\"logo\":{\"@id\":\"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.\",\"sameAs\":[\"https:\/\/www.ruianding.com\"],\"url\":\"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Enable Web Sign-in with Temporary Access Pass - \u6781\u7b80IT\uff5cSimpleIT","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/","og_locale":"en_US","og_type":"article","og_title":"Enable Web Sign-in with Temporary Access Pass - \u6781\u7b80IT\uff5cSimpleIT","og_description":"Overview This post will share how to implement Web Sign-in Feature, and this feature will allow the user sign-in Windows with the TAP (Temporary Access Pass). As the reminder, the Web Sign-in feature used to be the feature that can support 3rd party federation sign-in and MFA. For example, AAD Joined machine only supports 3rd [&hellip;]","og_url":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/","og_site_name":"\u6781\u7b80IT\uff5cSimpleIT","article_published_time":"2022-12-26T00:05:00+00:00","article_modified_time":"2025-03-18T09:43:30+00:00","og_image":[{"width":751,"height":173,"url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png","type":"image\/png"}],"author":"Ruian Ding","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ruian Ding","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#article","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/"},"author":{"name":"Ruian Ding","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"headline":"Enable Web Sign-in with Temporary Access Pass","datePublished":"2022-12-26T00:05:00+00:00","dateModified":"2025-03-18T09:43:30+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/"},"wordCount":889,"publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"image":{"@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png","keywords":["DRS","NGC","WHFB"],"articleSection":["Tutorial"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/","url":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/","name":"Enable Web Sign-in with Temporary Access Pass - \u6781\u7b80IT\uff5cSimpleIT","isPartOf":{"@id":"https:\/\/www.ruianding.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage"},"image":{"@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png","datePublished":"2022-12-26T00:05:00+00:00","dateModified":"2025-03-18T09:43:30+00:00","breadcrumb":{"@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#primaryimage","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2022\/12\/image.png","width":751,"height":173},{"@type":"BreadcrumbList","@id":"https:\/\/www.ruianding.com\/blog\/enable-web-sign-in-with-temporary-access-pass\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ruianding.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Enable Web Sign-in with Temporary Access Pass"}]},{"@type":"WebSite","@id":"https:\/\/www.ruianding.com\/blog\/#website","url":"https:\/\/www.ruianding.com\/blog\/","name":"Ruian's Tech Troubleshooting Toolbox","description":"Debug the World.","publisher":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b"},"alternateName":"\u4e01\u777f\u5b89\u7684\u6280\u672f\u5206\u4eab\u535a\u5ba2","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ruianding.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/440d88575b7dc819a4cefc8c4199db3b","name":"Ruian Ding","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","contentUrl":"https:\/\/www.ruianding.com\/blog\/wp-content\/uploads\/2023\/05\/logo.png","width":284,"height":284,"caption":"Ruian Ding"},"logo":{"@id":"https:\/\/www.ruianding.com\/blog\/#\/schema\/person\/image\/"},"description":"I am currently a Support Specialist at NIO, focusing on cloud-related issues for NIO Power. Previously, at Microsoft Entra ID, I specialized in identity and access management (IAM), including device registration, Windows Hello for Business (WHfB), multi-factor authentication (MFA), and single sign-on (SSO). In addition to my core expertise, I have a strong foundation in Active Directory, Servers, Cloud Computing, Network Administration, and Front-end Web Development. This diverse technical skill set enables me to effectively handle a wide range of challenges in a fast-paced IT environment.","sameAs":["https:\/\/www.ruianding.com"],"url":"https:\/\/www.ruianding.com\/blog\/author\/ruiand\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/75","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/comments?post=75"}],"version-history":[{"count":5,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/75\/revisions"}],"predecessor-version":[{"id":2672,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/posts\/75\/revisions\/2672"}],"wp:attachment":[{"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/media?parent=75"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/categories?post=75"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ruianding.com\/blog\/wp-json\/wp\/v2\/tags?post=75"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}