Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy

A security administrator needs to implement a solution that allows users to sign in to Microsoft Entra ID without requiring passwords, using a hardware device that meets FIDO2 standards. Which authentication method should the administrator configure?

  1. AMicrosoft Authenticator app
  2. BSMS-based authentication
  3. CFIDO2 Security Key
  4. DCertificate-based authentication
Show answer & explanation

Correct answer: C. FIDO2 Security Key

FIDO2 Security Keys provide a passwordless authentication method that uses hardware devices meeting FIDO2 standards, allowing users to sign in to Microsoft Entra ID securely without passwords.

Why the other options are wrong

  • A. The Microsoft Authenticator app is a software-based MFA method, not a hardware FIDO2 solution.
  • B. SMS-based authentication is a form of multi-factor authentication, but it is not passwordless and does not use FIDO2 hardware.
  • D. Certificate-based authentication uses digital certificates for authentication, which is different from FIDO2 security keys.

FIDO2 Security Key

A hardware-based authentication method that provides passwordless sign-in to Microsoft Entra ID and other services, adhering to FIDO2 standards.

  • Enables passwordless authentication.
  • Uses dedicated hardware devices.
  • Offers enhanced security against phishing.

Memory trick: FIDO's Key unlocks without a password.

More Describe the capabilities of Microsoft Entra questions