Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy

A small business is setting up its Microsoft Entra ID tenant. They want to ensure that users are prompted for a second verification method, such as a code from a mobile app or a phone call, when signing in. Which Microsoft Entra feature should they configure?

  1. AMicrosoft Entra ID Protection
  2. BMicrosoft Entra Application Proxy
  3. CMicrosoft Entra Connect Sync
  4. DMicrosoft Entra multifactor authentication (MFA)
Show answer & explanation

Correct answer: D. Microsoft Entra multifactor authentication (MFA)

Microsoft Entra multifactor authentication (MFA) adds a second layer of security by requiring users to provide two or more verification factors to gain access to resources. This directly addresses the requirement for a second verification method.

Why the other options are wrong

  • A. Microsoft Entra ID Protection detects and remediates identity-based risks, but MFA is the feature that enforces the second verification step.
  • B. Microsoft Entra Application Proxy publishes on-premises web applications externally, it does not directly manage sign-in verification methods.
  • C. Microsoft Entra Connect Sync is used for synchronizing on-premises directories with Microsoft Entra ID, not for authentication challenges.

Microsoft Entra multifactor authentication (MFA)

A security system that requires users to provide two or more verification methods to gain access to a resource, significantly enhancing security.

  • Adds an extra layer of security beyond just a password.
  • Common verification methods include phone calls, text messages, or authenticator apps.
  • Helps protect against credential theft and unauthorized access.

Memory trick: MFA: More Factors for Access.

More Describe the capabilities of Microsoft Entra questions