Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy
A security administrator needs to implement a solution that allows users to sign in to Microsoft Entra ID without requiring passwords, using a hardware device that meets FIDO2 standards. Which authentication method should the administrator configure?
- AMicrosoft Authenticator app
- BSMS-based authentication
- CFIDO2 Security Key
- DCertificate-based authentication
Show answer & explanationAnswer & explanation
Correct answer: C. FIDO2 Security Key
FIDO2 Security Keys provide a passwordless authentication method that uses hardware devices meeting FIDO2 standards, allowing users to sign in to Microsoft Entra ID securely without passwords.
Why the other options are wrong
- A. The Microsoft Authenticator app is a software-based MFA method, not a hardware FIDO2 solution.
- B. SMS-based authentication is a form of multi-factor authentication, but it is not passwordless and does not use FIDO2 hardware.
- D. Certificate-based authentication uses digital certificates for authentication, which is different from FIDO2 security keys.
FIDO2 Security Key
A hardware-based authentication method that provides passwordless sign-in to Microsoft Entra ID and other services, adhering to FIDO2 standards.
- Enables passwordless authentication.
- Uses dedicated hardware devices.
- Offers enhanced security against phishing.
Memory trick: FIDO's Key unlocks without a password.