Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy
A small business is setting up its Microsoft Entra ID tenant. They want to ensure that users are prompted for a second verification method, such as a code from a mobile app or a phone call, when signing in. Which Microsoft Entra feature should they configure?
- AMicrosoft Entra ID Protection
- BMicrosoft Entra Application Proxy
- CMicrosoft Entra Connect Sync
- DMicrosoft Entra multifactor authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Entra multifactor authentication (MFA)
Microsoft Entra multifactor authentication (MFA) adds a second layer of security by requiring users to provide two or more verification factors to gain access to resources. This directly addresses the requirement for a second verification method.
Why the other options are wrong
- A. Microsoft Entra ID Protection detects and remediates identity-based risks, but MFA is the feature that enforces the second verification step.
- B. Microsoft Entra Application Proxy publishes on-premises web applications externally, it does not directly manage sign-in verification methods.
- C. Microsoft Entra Connect Sync is used for synchronizing on-premises directories with Microsoft Entra ID, not for authentication challenges.
Microsoft Entra multifactor authentication (MFA)
A security system that requires users to provide two or more verification methods to gain access to a resource, significantly enhancing security.
- Adds an extra layer of security beyond just a password.
- Common verification methods include phone calls, text messages, or authenticator apps.
- Helps protect against credential theft and unauthorized access.
Memory trick: MFA: More Factors for Access.