Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
An organization wants to implement a passwordless authentication strategy for its mobile workforce. They require a method that allows users to sign in to Microsoft Entra ID and connected applications using a cryptographic key stored on their device, without ever typing a password. Which Microsoft Entra authentication method supports this requirement?
- AFIDO2 security keys
- BPassword Hash Synchronization (PHS)
- CPass-through Authentication (PTA)
- DMultifactor Authentication (MFA)
Show answer & explanationAnswer & explanation
Correct answer: A. FIDO2 security keys
FIDO2 security keys are a strong, phishing-resistant, and passwordless authentication method supported by Microsoft Entra ID. They use public-key cryptography to securely sign in users without passwords, meeting the requirement for a cryptographic key on a device.
Why the other options are wrong
- B. PHS synchronizes password hashes, still reliant on passwords.
- C. PTA validates passwords against on-premises AD, still reliant on passwords.
- D. MFA adds a second factor but doesn't inherently remove the password itself, unless combined with a passwordless method.
FIDO2 Security Keys
A phishing-resistant, passwordless authentication method that uses public-key cryptography and device-bound security keys.
- Users sign in with a key and a PIN/biometric, no password.
- Provides strong protection against phishing and credential theft.
- Supported by Microsoft Entra ID for passwordless access.
Memory trick: FIDO2 is your 'fingerprint ID' for passwordless, secure sign-in.