1. Definitions
The following terms are used throughout this policy:
- TAP (Temporary Access Pass) — A time-limited passcode generated in Microsoft Entra ID that allows an authorized IT staff member to authenticate to a user’s account without using the user’s password.
- TAP Issuer — An authorized IT staff member who has been granted the Authentication Administrator role in Entra ID and is permitted to generate TAPs within the bounds of this policy.
- Entra ID — Microsoft’s cloud identity platform used by Dartmouth College for authentication, access management, and TAP administration.
- Autopilot — Microsoft’s cloud-based device enrollment and provisioning service used to configure new or re-imaged Windows devices.
- Intune — Microsoft’s device management platform used by Dartmouth College to manage and enforce policy on institutional endpoints.
- CyberArk — Dartmouth’s privileged access management tool. TAP Issuers must use their department-assigned CyberArk account when generating TAPs.
- TeamDynamix (TDX) — Dartmouth College’s IT ticketing and knowledge base platform. TAP issuance must be documented in the originating TDX ticket.
- OOBE (Out of Box Experience) — The initial setup process presented on a new or re-imaged Windows device before it has been enrolled in Entra ID or Intune.
2. Purpose
This policy establishes the authorized use of Temporary Access Pass (TAP) within Dartmouth College’s Microsoft Entra ID environment. TAP is a time-limited, IT-issued passcode that enables eligible users to authenticate without a password for a defined, scoped purpose. It is a privileged function and must be used only within the boundaries defined by this policy.
This policy defines:
- Who is authorized to generate TAP credentials
- What verification is required before issuance
- What use cases are permitted
- What logging and accountability requirements apply
- What limitations and prohibitions govern TAP use
3. Scope
This policy applies to all Dartmouth College IT personnel who hold the TAP Issuer role in Microsoft Entra ID. Authorized issuer groups are defined in Section 4.3. TAP is intended solely for use by authorized IT staff in the performance of their duties. TAP is not issued to or used by end users under any circumstances.
4. Roles and Authorization
4.1 TAP Issuer Role
The TAP Issuer role (Authentication Administrator in Entra ID) is a privileged role that must be formally assigned and actively managed. The TAP Issuer role is administered by Infrastructure Services through Entra ID group membership. Role requests and changes are submitted via TeamDynamix. Access to the TAP Issuer role is granted based on an individual’s position and organizational group membership as defined in Section 4.3. No individual receives this role based on personal request alone. Any expansion of TAP Issuer access beyond the defined positions and groups requires review by the Information Security team and approval by Infrastructure Services leadership. The following requirements apply to all TAP Issuers:
- Must be a full-time Dartmouth College employee in an IT support capacity
- Student workers are not eligible to hold the TAP Issuer role
- Must use the CyberArk privileged account assigned to their department when issuing TAP; standard user credentials must not be used for this function
- Must have this policy reviewed with them by their manager or team leader prior to role assignment. The manager initiates role assignment by submitting a request to Infrastructure Services via TeamDynamix.
- Role assignment is managed through Entra ID group membership. Department leadership is responsible for reviewing their group annually and submitting a request to Infrastructure Services via TeamDynamix if any changes are needed.
4.2 Leadership Accountability
Department leadership is accountable for ensuring that the TAP Issuer role is assigned only to eligible individuals within their area and that those individuals understand and adhere to this policy. This accountability is non-delegable and includes:
- Ensuring no individual receives the TAP Issuer role without first having this policy reviewed with them as described in Section 12
- Maintaining an accurate and current list of staff within their department who hold the TAP Issuer role
- Promptly submitting a request to Infrastructure Services via TeamDynamix to remove the TAP Issuer role when a staff member changes role, transfers, or separates from the institution
- Addressing policy violations within their team in coordination with the Manager of Infrastructure Services
4.3 Authorized Issuer Groups
- Client Technology Consulting support personnel
- Computer Store endpoint management staff
- Computer Store repair technicians
- Infrastructure Services staff
- Kemeny Team (Identity and Authentication) — as holders of the Privileged Authentication Administrator role, the Kemeny Team is authorized to issue TAP for all account types including privileged and administrative accounts
- Other client support teams, as reviewed by the Information Security office and approved by Infrastructure Services. Approvals must be documented in a TeamDynamix ticket.
5. Permitted Use Cases
5.1 New Device Provisioning (Autopilot)
This is the primary use case for authorized TAP Issuers in device support roles. During Autopilot enrollment, the issuer uses TAP to authenticate to the device on behalf of the user in order to complete the provisioning process, enroll the device in Intune, and configure required applications. The user’s own credentials are not required during this process.
This use case applies to faculty and staff only. Student BYOD devices are not eligible for provisioning via TAP under this policy.
5.2 Device Drop-Off Troubleshooting
TAP may be issued when a user has dropped off their device for hands-on troubleshooting and the technician requires authenticated access to replicate or resolve an application issue on behalf of the user. The user must be informed that a TAP will be used for this purpose prior to leaving the device.
6. Identity Verification Requirements
Before generating a TAP, the issuer must confirm the identity of the account holder. The issuer must not generate a TAP based solely on a verbal or unverified request. The method of verification must be noted in the originating TeamDynamix ticket. Acceptable verification methods include:
- Originating TDX ticket — A ticket opened by or on behalf of a known user through standard channels serves as identity confirmation.
- In-person with Dartmouth ID — User presents their Dartmouth ID card at drop-off. Preferred method for device drop-off troubleshooting.
- Manager or supervisor confirmation — The user’s manager contacts the help desk directly via their Dartmouth email to confirm the user and task.
- Institutional directory record match — Issuer confirms the account belongs to an active employee by checking an authoritative institutional directory before proceeding.
Phone calls, Teams messages, or other verbal requests are not acceptable as standalone verification.
7. TAP Configuration Requirements
TAP must be configured in Entra ID as follows:
| Setting |
Required Value |
| Enabled For |
A scoped security group, not all users — keeps eligibility limited to faculty and staff |
| Minimum Lifetime |
5 minutes — shortest duration an issuer can set for a TAP |
| Default Lifetime |
120 minutes (2 hours) — what pre-populates when an issuer generates a TAP; covers most provisioning sessions |
| Maximum Lifetime |
120 minutes (2 hours) — longest duration an issuer can set; accommodates complex provisioning without leaving a TAP open for an extended period |
| One-Time Use |
Disabled — a TAP is invalidated after first use, limiting exposure if it is intercepted or shared |
| Passcode Length |
15 characters — balances ease of entry with resistance to guessing |
| Access Method |
Issuers must use the CyberArk privileged account assigned to their department; standard user credentials may not be used |
Note: Conditional Access policies should be reviewed to ensure TAP is not inadvertently blocked, particularly during Autopilot provisioning when the device is not yet enrolled at first sign-in.
8. Prohibited Actions
The following actions are strictly prohibited for all TAP Issuers:
- Generating a TAP without completing documented identity verification
- Generating a TAP for your own account
- Sharing a TAP with any individual who is not the verified account holder. A TAP may only be communicated directly to the account holder when the technician cannot physically access the device — such as during a remote support session. TAP must never be shared with third parties, colleagues, or anyone other than the verified account holder.
- Generating a TAP for a privileged or administrative account without authorization. Issuers who are unsure whether an account qualifies as privileged or administrative should consult with the Information Security team before proceeding.
- Generating a TAP without creating an associated TeamDynamix ticket with required documentation
- Failing to deactivate a TAP immediately upon completion of the task for which it was issued. Although a single-use TAP is invalidated after first use, issuers must manually invalidate any unused TAP in Entra ID as soon as the work is complete.
9. Logging and Audit
All TAP issuance activity is subject to audit. The following logging and review requirements apply:
- All TAP generation events are captured in Microsoft Entra ID audit logs automatically
- TAP issuance must be documented within the originating TeamDynamix ticket for the task being performed (e.g., device replacement, application troubleshooting). A separate ticket is not required solely for TAP issuance.
- The Manager of Infrastructure Services will conduct a quarterly review of TAP issuance logs to identify anomalous patterns, in coordination with department leadership
- Issuers generating TAPs with no associated ticket or at elevated frequency will be flagged for review.
- Audit findings will be reported to the Manager of Infrastructure Services on a quarterly basis
10. Policy Violations
Violations of this policy will be reviewed by the Manager of Infrastructure Services and may result in:
- Immediate removal of the TAP Issuer role
- Escalation to Human Resources in accordance with Dartmouth College employment policies
- Escalation to the Dartmouth College Information Security team if a breach of account integrity is suspected
Good-faith procedural errors (e.g., a ticket number omitted but otherwise compliant) will be addressed through coaching and retraining on first occurrence.
11. Policy Review and Maintenance
This policy will be reviewed annually by Infrastructure Services leadership and updated as needed based on:
- Changes to Microsoft Entra ID TAP functionality or configuration options
- Changes to Dartmouth’s device provisioning or onboarding workflows
- Audit findings or incident outcomes
- Changes to applicable compliance frameworks or institutional security policy
Policy changes will be communicated to all active TAP Issuers. Managers and team leaders of authorized groups must review any updated policy with their staff prior to continued use of the TAP Issuer role.
12. Policy Review by Manager or Team Lead
In lieu of individual signatures, the manager or team leader of each authorized group is responsible for ensuring that all individuals within their group who hold the TAP Issuer role have been made aware of this policy and understand the expectations it places on them. This review must occur:
- Before the TAP Issuer role is assigned to any new staff member within the group
- Annually, as part of the role re-affirmation process described in Section 4.1
- Any time this policy is updated, prior to continued use of the TAP Issuer role by existing staff
The manager or team leader must retain a record of this review within their department. No individual-level signature is required at this time.