Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
An organization wants to simplify the sign-in experience for its mobile workforce by allowing them to authenticate to Microsoft Entra ID using their smartphones without entering passwords. The solution must support strong, multi-factor authentication. Which method best achieves this?
- AMicrosoft Authenticator app passwordless sign-in
- BPass-through Authentication (PTA)
- CFederated authentication with AD FS
- DPassword Hash Synchronization (PHS)
Show answer & explanationAnswer & explanation
Correct answer: A. Microsoft Authenticator app passwordless sign-in
The Microsoft Authenticator app's passwordless sign-in allows users to authenticate by approving a notification on their mobile device, providing strong, MFA-enabled, and passwordless access to Microsoft Entra ID. This is ideal for a mobile workforce.
Why the other options are wrong
- B. PTA is a hybrid identity method for on-premises password validation, not passwordless.
- C. Federated authentication is a complex infrastructure for identity, not a direct passwordless MFA solution for mobile users.
- D. PHS is a hybrid identity method, not a passwordless MFA solution.
Microsoft Authenticator App Passwordless Sign-in
A passwordless authentication method where users approve a notification on their Microsoft Authenticator app on a mobile device to sign in to Microsoft Entra ID, combining security with convenience.
- Provides strong, MFA-enabled authentication
- Eliminates passwords for sign-in
- Leverages biometrics on the mobile device for security
Memory trick: Your phone is the key, no typing required.