Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A company wants to implement a passwordless authentication strategy where users can sign in to Microsoft Entra ID using a physical security key that supports public-key cryptography. Which authentication method should they deploy?

  1. APassword Hash Synchronization (PHS)
  2. BPass-through Authentication (PTA)
  3. CFIDO2 security keys
  4. DSAML-based Single Sign-On (SSO)
Show answer & explanation

Correct answer: C. FIDO2 security keys

FIDO2 security keys are a robust passwordless authentication method that uses public-key cryptography, providing strong phishing-resistant authentication for Microsoft Entra ID.

Why the other options are wrong

  • A. PHS is a hybrid identity method for synchronizing password hashes, not a passwordless authentication method.
  • B. PTA is a hybrid identity method where Entra ID passes credentials to on-premises AD for validation, not passwordless.
  • D. SAML-based SSO is an authentication protocol, but doesn't inherently imply passwordless authentication with physical keys.

FIDO2 (Fast Identity Online 2) security keys

A passwordless authentication standard that uses public-key cryptography and physical security keys to provide strong, phishing-resistant authentication for web services.

  • Uses asymmetric cryptography (public/private key pairs)
  • Offers phishing resistance
  • Compatible with various devices and platforms

Memory trick: Physical key unlocks access, no password needed.

More Describe the capabilities of Microsoft Entra questions