Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A company wants to implement a passwordless authentication strategy where users can sign in to Microsoft Entra ID using a physical security key that supports public-key cryptography. Which authentication method should they deploy?
- APassword Hash Synchronization (PHS)
- BPass-through Authentication (PTA)
- CFIDO2 security keys
- DSAML-based Single Sign-On (SSO)
Show answer & explanationAnswer & explanation
Correct answer: C. FIDO2 security keys
FIDO2 security keys are a robust passwordless authentication method that uses public-key cryptography, providing strong phishing-resistant authentication for Microsoft Entra ID.
Why the other options are wrong
- A. PHS is a hybrid identity method for synchronizing password hashes, not a passwordless authentication method.
- B. PTA is a hybrid identity method where Entra ID passes credentials to on-premises AD for validation, not passwordless.
- D. SAML-based SSO is an authentication protocol, but doesn't inherently imply passwordless authentication with physical keys.
FIDO2 (Fast Identity Online 2) security keys
A passwordless authentication standard that uses public-key cryptography and physical security keys to provide strong, phishing-resistant authentication for web services.
- Uses asymmetric cryptography (public/private key pairs)
- Offers phishing resistance
- Compatible with various devices and platforms
Memory trick: Physical key unlocks access, no password needed.