Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard

An organization wants to implement a passwordless authentication strategy for its mobile workforce. They require a method that allows users to sign in to Microsoft Entra ID and connected applications using a cryptographic key stored on their device, without ever typing a password. Which Microsoft Entra authentication method supports this requirement?

  1. AFIDO2 security keys
  2. BPassword Hash Synchronization (PHS)
  3. CPass-through Authentication (PTA)
  4. DMultifactor Authentication (MFA)
Show answer & explanation

Correct answer: A. FIDO2 security keys

FIDO2 security keys are a strong, phishing-resistant, and passwordless authentication method supported by Microsoft Entra ID. They use public-key cryptography to securely sign in users without passwords, meeting the requirement for a cryptographic key on a device.

Why the other options are wrong

  • B. PHS synchronizes password hashes, still reliant on passwords.
  • C. PTA validates passwords against on-premises AD, still reliant on passwords.
  • D. MFA adds a second factor but doesn't inherently remove the password itself, unless combined with a passwordless method.

FIDO2 Security Keys

A phishing-resistant, passwordless authentication method that uses public-key cryptography and device-bound security keys.

  • Users sign in with a key and a PIN/biometric, no password.
  • Provides strong protection against phishing and credential theft.
  • Supported by Microsoft Entra ID for passwordless access.

Memory trick: FIDO2 is your 'fingerprint ID' for passwordless, secure sign-in.

More Describe the capabilities of Microsoft Entra questions