โ† All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Entra Authentication Methods flashcards as text
  1. What is the role of a 'passkey' in Microsoft Entra ID authentication?

    Answer: A FIDO2-based passwordless credential tied to biometrics or device PIN

    Passkeys are FIDO2-based credentials that replace passwords, using device biometrics or PIN combined with public key cryptography for phishing-resistant sign-in.

  2. An administrator wants to enforce that all users in a high-security group use only phishing-resistant authentication methods. What is the correct approach in Microsoft Entra ID?

    Answer: Create a Conditional Access policy requiring phishing-resistant MFA strength for the group

    Conditional Access Authentication Strength policies allow admins to require specific method tiers (like phishing-resistant MFA) for particular users, groups, or scenarios.

  3. Which protocol do FIDO2 security keys use when communicating with a browser or platform during authentication?

    Answer: WebAuthn/CTAP2

    FIDO2 keys use the WebAuthn API (browser side) and CTAP2 protocol (between authenticator and device) to perform cryptographic authentication.

  4. How does Microsoft Entra ID handle authentication for users in regions where SMS delivery is unreliable?

    Answer: Admins can enable alternative methods such as Microsoft Authenticator or FIDO2 keys in the Authentication Methods policy

    Admins configure the Authentication Methods policy to enable alternative methods like Microsoft Authenticator or FIDO2, giving users options that don't rely on SMS infrastructure.

  5. What is the difference between MFA and passwordless authentication in Microsoft Entra ID?

    Answer: MFA always requires a password plus a second factor; passwordless replaces the password entirely with strong factors

    MFA combines a password with additional factors, while passwordless authentication eliminates the password and uses strong factors like biometrics or security keys alone.

  6. Which Microsoft Entra ID report helps administrators identify users who have not yet registered for MFA?

    Answer: Authentication Methods Registration Report

    The Authentication Methods Registration Report in Microsoft Entra ID shows which users have registered specific authentication methods and identifies those who haven't completed registration.

  7. A company is migrating from per-user MFA settings to Conditional Access-based MFA. What should admins do to avoid conflicts?

    Answer: Disable per-user MFA for users covered by Conditional Access policies to prevent double prompts

    Running per-user MFA alongside Conditional Access MFA can cause redundant authentication prompts, so admins should turn off per-user MFA for users governed by CA policies.