Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A security auditor recommends that a company implement a solution where users are prompted for an additional verification step, such as a biometric scan or a code from an authenticator app, when signing in from an unmanaged device or an unfamiliar location. Which Microsoft Entra capability directly addresses this recommendation?
- AMicrosoft Entra Identity Governance
- BMicrosoft Entra Domain Services
- CMicrosoft Entra multifactor authentication (MFA)
- DMicrosoft Entra Password Protection
Show answer & explanationAnswer & explanation
Correct answer: C. Microsoft Entra multifactor authentication (MFA)
Multifactor authentication (MFA) requires users to provide two or more verification factors to gain access, significantly enhancing security, especially from unmanaged devices or unfamiliar locations.
Why the other options are wrong
- A. Identity Governance manages identity and access lifecycle, including access reviews and entitlement management.
- B. Domain Services provides managed domain services for Azure-hosted virtual machines.
- D. Password Protection prevents weak or banned passwords from being used.
Microsoft Entra MFA
A security measure requiring users to provide two or more verification factors to prove their identity during sign-in.
- Adds an extra layer of security beyond just a password
- Supports various methods: app notifications, codes, biometrics, hardware tokens
- Can be enforced conditionally based on risk factors
Memory trick: More factors mean more security for your login.