Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
An organization wants to simplify the sign-in experience for its mobile workforce by allowing them to authenticate to Microsoft Entra ID without passwords, using a secure, phishing-resistant method that leverages hardware-backed security. Which authentication method should they prioritize for implementation?
- ASMS-based multifactor authentication
- BPassword hash synchronization
- CFIDO2 security keys
- DMicrosoft Authenticator app notifications
Show answer & explanationAnswer & explanation
Correct answer: C. FIDO2 security keys
FIDO2 security keys offer a strong, phishing-resistant, hardware-backed passwordless authentication method. They are ideal for mobile workforces looking for a simplified and highly secure sign-in experience to Microsoft Entra ID.
Why the other options are wrong
- A. SMS MFA is not phishing-resistant and relies on phone network security.
- B. Password hash synchronization is a hybrid identity synchronization method, not an authentication method itself, and still relies on passwords.
- D. Authenticator app notifications are secure but still rely on a mobile device and can be susceptible to advanced phishing attacks if not carefully implemented.
FIDO2 Security Keys
A hardware-backed, phishing-resistant, passwordless authentication method that uses public-key cryptography to verify user identity.
- Provides strong, passwordless authentication to Microsoft Entra ID
- Resistant to phishing attacks due to device-bound credentials
- Leverages hardware security for enhanced protection
Memory trick: FIDO2 keys are your ultimate passwordless, anti-phishing shield.