Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
An organization wants to simplify the sign-in experience for its users by allowing them to authenticate to Microsoft Entra ID without typing a password, using a strong, phishing-resistant method. This method should leverage hardware-backed security keys or biometric authentication built into devices. Which passwordless authentication method in Microsoft Entra ID directly supports this requirement?
- AFIDO2 security keys
- BPassword Hash Synchronization (PHS)
- CSMS-based authentication
- DMicrosoft Authenticator app (passwordless)
Show answer & explanationAnswer & explanation
Correct answer: A. FIDO2 security keys
FIDO2 security keys provide a strong, phishing-resistant, hardware-backed passwordless authentication method. They allow users to sign in to Microsoft Entra ID using a physical key or biometric authentication, fulfilling the requirement for a simplified, secure, passwordless experience.
Why the other options are wrong
- B. PHS is a synchronization method for passwords, not a passwordless authentication method.
- C. SMS-based authentication uses an SMS code, but it's not phishing-resistant and not hardware-backed.
- D. Microsoft Authenticator app (passwordless) is a strong passwordless method, but FIDO2 specifically highlights hardware-backed security keys or biometrics built into devices as its primary mechanism.
FIDO2 security keys
A passwordless authentication standard that enables users to sign in to online services using a physical security key or built-in device biometrics, providing strong, phishing-resistant authentication.
- Offers phishing resistance due to unique device credentials.
- Uses public-key cryptography for strong security.
- Can be physical USB keys or built-in biometric sensors (e.g., Windows Hello).
- Compliant with FIDO2 and WebAuthn standards.
Memory trick: FIDO2 keys: Your digital key, no password, no phish.