Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A security architect is designing an identity solution for a company that wants to eliminate passwords for enhanced security and a streamlined user experience. They specifically want users to be able to sign in to Microsoft Entra ID-connected applications using a physical security key that supports strong, phishing-resistant authentication. Which authentication method should the architect recommend?
- AFIDO2 security keys
- BPassword hash synchronization
- CSMS-based multifactor authentication
- DMicrosoft Authenticator app passwordless sign-in
Show answer & explanationAnswer & explanation
Correct answer: A. FIDO2 security keys
FIDO2 security keys provide a highly secure, phishing-resistant, and passwordless authentication method. They are physical devices that store cryptographic credentials, making them an excellent choice for organizations aiming to eliminate passwords and enhance security.
Why the other options are wrong
- B. Password hash synchronization is a method for synchronizing passwords from on-premises AD to Microsoft Entra ID, not a passwordless authentication method.
- C. SMS-based MFA is not passwordless and is susceptible to phishing and SIM swap attacks.
- D. Microsoft Authenticator app passwordless sign-in is a passwordless option, but the scenario specifically mentions a 'physical security key'.
FIDO2 Security Keys
A passwordless authentication method that uses physical hardware devices to provide strong, phishing-resistant authentication based on public-key cryptography.
- Physical security key for authentication
- Passwordless and phishing-resistant
- Based on public-key cryptography (WebAuthn standard)
Memory trick: FIDO2: 'Fingerprint ID, Only Done Once' with a key.