Easy1 markMultiple Choice

AZ-305 · Question 13 · Domain 1.2: Authentication and Authorization

Your company wants to eliminate passwords for all employee authentications to Azure and Microsoft 365 to mitigate phishing attacks.

You need to design a passwordless authentication strategy. The solution must support employees who work entirely from personal mobile devices (BYOD) and do not have company-issued laptops or hardware security keys.

Which passwordless authentication method should you recommend?

Answer options:

A.

Windows Hello for Business

B.

FIDO2 security keys

C.

Microsoft Authenticator app

D.

Certificate-based authentication (CBA)

How to approach this question

Match the passwordless options to the constraints: no laptops (rules out Windows Hello), no hardware keys (rules out FIDO2).

Full Answer

C.Microsoft Authenticator app✓ Correct
Microsoft Authenticator app
Microsoft Entra ID supports three primary passwordless authentication methods: Windows Hello for Business, FIDO2 security keys, and the Microsoft Authenticator app. Because the employees use personal mobile devices and lack hardware keys or company laptops, the Microsoft Authenticator app (configured for phone sign-in) is the only viable passwordless solution.

Common mistakes

Selecting FIDO2 because it is highly secure, ignoring the constraint that users do not have hardware keys.

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 4

55 questions · hints · full answers · grading

More questions from this exam