SC-900 - Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods Questions and Answers — Questions and Answers
Question 1: A new employee is starting, and an administrator needs to provide them with a method to sign in and register for passwordless authentication for the first time. The employee does not yet have a corporate device or any registered authentication methods. Which Microsoft Entra authentication method is specifically designed for this onboarding scenario?
- FIDO2 Security Key
- Microsoft Authenticator app
- Temporary Access Pass (TAP) (Correct answer)
- SMS message
Correct answer: Temporary Access Pass (TAP)
A Temporary Access Pass (TAP) is a time-limited passcode that can be used to onboard other authentication methods, including passwordless ones like the Microsoft Authenticator app or a FIDO2 key. It is ideal for new users who need to register their permanent authentication methods without first needing a password.
Question 2: Which of the following authentication methods is considered the most resistant to phishing attacks?
- One-time passcode (OTP) via SMS
- FIDO2 Security Key (Correct answer)
- Push notification via mobile app
- Email with a one-time passcode
Correct answer: FIDO2 Security Key
FIDO2 security keys are a form of passwordless authentication that is highly resistant to phishing. They use public-key cryptography and require the physical presence of the key, making it extremely difficult for an attacker to steal credentials through a fake website or social engineering.
Question 3: A company wants to enable passwordless sign-in for its users. They want to provide an option that uses the employee's company-issued smartphone. Which feature of the Microsoft Authenticator app should be configured?
- One-time passcodes (OTP)
- Passwordless sign-in (phone sign-in) (Correct answer)
- SMS-based authentication
- Security questions
Correct answer: Passwordless sign-in (phone sign-in)
The Microsoft Authenticator app supports passwordless sign-in, also known as phone sign-in. With this method, the user enters their username, and then receives a notification on their registered device. They can approve the sign-in directly from the app using a biometric gesture (like a fingerprint) or a PIN, eliminating the need for a password.
Question 4: An organization is configuring its Self-Service Password Reset (SSPR) policy. They want to ensure users have multiple ways to prove their identity before being allowed to reset their password. Which of the following is NOT a valid authentication method that can be used for SSPR in Microsoft Entra ID?
- Email one-time passcode (OTP)
- Security questions
- Windows Hello for Business (Correct answer)
- Mobile app notification
Correct answer: Windows Hello for Business
While Windows Hello for Business is a strong, passwordless authentication method for signing into a device, it is used for primary authentication, not as a method for account recovery during a Self-Service Password Reset (SSPR) flow. SSPR relies on methods like email, phone calls, SMS, security questions, or the Authenticator app to verify the user's identity when they have forgotten their password.
Question 5: When configuring the FIDO2 security key authentication method policy in the Microsoft Entra admin center, an administrator chooses to set "Enforce attestation" to "Yes". What is the primary purpose of this setting?
- To require users to provide a fingerprint every time they use the key.
- To ensure that the security key model is genuine and from a legitimate vendor. (Correct answer)
- To force users to register their key from a trusted network location.
- To log all sign-in attempts using FIDO2 keys for auditing purposes.
Correct answer: To ensure that the security key model is genuine and from a legitimate vendor.
The "Enforce attestation" setting for FIDO2 security keys verifies the Authenticator Attestation GUID (AAGUID) of the key during registration. This process ensures that the key is from a specific, trusted manufacturer and model, preventing the use of unapproved or potentially compromised hardware.
Question 6: A user can leverage the Microsoft Authenticator app for multiple purposes. Which of the following lists best describes the capabilities of the Microsoft Authenticator app?
- Only for generating one-time passcodes.
- For passwordless sign-in, MFA push notifications, and generating OATH one-time passcodes. (Correct answer)
- Only for approving multi-factor authentication (MFA) push notifications.
- For resetting passwords and unlocking BitLocker-encrypted drives.
Correct answer: For passwordless sign-in, MFA push notifications, and generating OATH one-time passcodes.
The Microsoft Authenticator app is a versatile tool that can be used for passwordless phone sign-in, approving MFA push notifications, and as a software token to generate OATH standard one-time passcodes (verification codes).
A new employee is starting, and an administrator needs to provide them with a method to sign in and register for passwordless authentication for the first time.
The employee does not yet have a corporate device or any registered authentication methods.
Which Microsoft Entra authentication method is specifically designed for this onboarding scenario?