Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A security architect is designing an identity solution for a company that wants to eliminate passwords for enhanced security and a streamlined user experience. They specifically want to leverage biometric authentication (e.g., fingerprint, facial recognition) directly from users' devices. Which passwordless authentication method aligns best with this requirement?

  1. ASMS-based Multi-Factor Authentication (MFA)
  2. BMicrosoft Authenticator app passwordless sign-in
  3. CFIDO2 security keys
  4. DPassword hash synchronization
Show answer & explanation

Correct answer: B. Microsoft Authenticator app passwordless sign-in

The Microsoft Authenticator app passwordless sign-in allows users to sign in by approving a notification on their mobile device or using biometrics (fingerprint, face ID) directly from the app. This meets the requirement for passwordless biometric authentication directly from users' devices.

Why the other options are wrong

  • A. SMS-based MFA still relies on a password for the first factor and SMS as the second, not truly passwordless.
  • C. FIDO2 security keys are a passwordless option, but they are physical hardware devices, not biometric authentication directly from a user's existing device.
  • D. Password hash synchronization is an identity synchronization method, not an authentication method, and certainly not passwordless.

Microsoft Authenticator app passwordless sign-in

A passwordless authentication method where users approve a notification on their Microsoft Authenticator app, often using a PIN or biometric gesture (fingerprint, facial recognition) on their mobile device.

  • Eliminates the need for a password.
  • Leverages biometrics or PIN on the mobile device.
  • Provides a seamless and secure sign-in experience.

Memory trick: The Authenticator app is your phone's biometric bouncer.

More Describe the capabilities of Microsoft Entra questions