Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A security architect is designing an identity solution for a company that wants to eliminate passwords for better security and user experience. They plan to use hardware devices that provide strong, phishing-resistant authentication. Which Microsoft Entra authentication method should the architect recommend?

  1. AMicrosoft Entra Password Protection
  2. BFIDO2 security keys
  3. CPassword Hash Synchronization (PHS)
  4. DPass-through Authentication (PTA)
Show answer & explanation

Correct answer: B. FIDO2 security keys

FIDO2 security keys are a strong, phishing-resistant, and passwordless authentication method. They use public-key cryptography and are designed to replace passwords entirely, aligning with the goal of eliminating passwords.

Why the other options are wrong

  • A. Microsoft Entra Password Protection helps prevent weak passwords but does not eliminate passwords.
  • C. Password Hash Synchronization (PHS) is a hybrid identity method that syncs password hashes, still relying on passwords.
  • D. Pass-through Authentication (PTA) uses on-premises AD to validate passwords, also relying on passwords.

FIDO2 Security Keys

A passwordless authentication method that uses hardware security keys and public-key cryptography for strong, phishing-resistant authentication.

  • Phishing resistant, as authentication is tied to a specific origin
  • Offers a true passwordless experience
  • Supported by major web browsers and operating systems

Memory trick: Keys are better than remembering words.

More Describe the capabilities of Microsoft Entra questions