Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A security architect is designing an identity solution for a company that wants to eliminate passwords for better security and user experience. They plan to use hardware devices that provide strong, phishing-resistant authentication. Which Microsoft Entra authentication method should the architect recommend?
- AMicrosoft Entra Password Protection
- BFIDO2 security keys
- CPassword Hash Synchronization (PHS)
- DPass-through Authentication (PTA)
Show answer & explanationAnswer & explanation
Correct answer: B. FIDO2 security keys
FIDO2 security keys are a strong, phishing-resistant, and passwordless authentication method. They use public-key cryptography and are designed to replace passwords entirely, aligning with the goal of eliminating passwords.
Why the other options are wrong
- A. Microsoft Entra Password Protection helps prevent weak passwords but does not eliminate passwords.
- C. Password Hash Synchronization (PHS) is a hybrid identity method that syncs password hashes, still relying on passwords.
- D. Pass-through Authentication (PTA) uses on-premises AD to validate passwords, also relying on passwords.
FIDO2 Security Keys
A passwordless authentication method that uses hardware security keys and public-key cryptography for strong, phishing-resistant authentication.
- Phishing resistant, as authentication is tied to a specific origin
- Offers a true passwordless experience
- Supported by major web browsers and operating systems
Memory trick: Keys are better than remembering words.