Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard

An organization wants to simplify the sign-in experience for its mobile workforce by allowing them to authenticate to Microsoft Entra ID without passwords, using a secure, phishing-resistant method that leverages hardware-backed security. Which authentication method should they prioritize for implementation?

  1. ASMS-based multifactor authentication
  2. BPassword hash synchronization
  3. CFIDO2 security keys
  4. DMicrosoft Authenticator app notifications
Show answer & explanation

Correct answer: C. FIDO2 security keys

FIDO2 security keys offer a strong, phishing-resistant, hardware-backed passwordless authentication method. They are ideal for mobile workforces looking for a simplified and highly secure sign-in experience to Microsoft Entra ID.

Why the other options are wrong

  • A. SMS MFA is not phishing-resistant and relies on phone network security.
  • B. Password hash synchronization is a hybrid identity synchronization method, not an authentication method itself, and still relies on passwords.
  • D. Authenticator app notifications are secure but still rely on a mobile device and can be susceptible to advanced phishing attacks if not carefully implemented.

FIDO2 Security Keys

A hardware-backed, phishing-resistant, passwordless authentication method that uses public-key cryptography to verify user identity.

  • Provides strong, passwordless authentication to Microsoft Entra ID
  • Resistant to phishing attacks due to device-bound credentials
  • Leverages hardware security for enhanced protection

Memory trick: FIDO2 keys are your ultimate passwordless, anti-phishing shield.

More Describe the capabilities of Microsoft Entra questions