Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

You are designing an identity solution for a multinational company that uses Microsoft Entra ID. The company has a requirement that all users must authenticate using biometrics or FIDO2 security keys. Which Entra ID feature should you configure?

⚠ Common exam trap

Many candidates confuse the authentication method itself (passwordless authentication) with the policy mechanism (Conditional Access) that enforces its use, leading them to select Option A instead of D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conditional Access policies

Conditional Access policies in Microsoft Entra ID allow you to enforce authentication strength requirements, such as requiring biometrics or FIDO2 security keys, by targeting specific user groups or applications. This is achieved by configuring a Conditional Access policy with the 'Require multifactor authentication' control and integrating with authentication methods like Windows Hello for Business or FIDO2 security keys, ensuring that only passwordless authentication methods meeting the company's biometric or FIDO2 requirement are permitted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Passwordless authentication

    Why it's wrong here

    While passwordless authentication eliminates traditional passwords, it encompasses multiple methods such as FIDO2 security keys, Windows Hello for Business, and phone-based sign-in via Microsoft Authenticator or SMS OTP. Critically, not all of these are phishing-resistant—FIDO2 and Windows Hello are hardware-backed and resistant to phishing, but SMS OTP and one-time codes are still vulnerable to social engineering or man-in-the-middle attacks. Merely enabling passwordless does not guarantee the phishing-resistant requirement; a Conditional Access policy must be used to enforce a specific, phishing-resistant method.

  • ✗

    Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection is a risk-based engine that continuously evaluates sign-in and user risk (e.g., impossible travel, leaked credentials, anonymous IP addresses) and can trigger actions like requiring MFA or password change when risk is detected. However, it does not enforce a particular authentication method itself—it only reacts to risk signals and cannot mandate the use of FIDO2 or Windows Hello for Business. To strictly require phishing-resistant authentication, you must configure a Conditional Access policy that explicitly selects those methods, not rely on Identity Protection as the enforcement point.

  • ✗

    Entra Verified ID

    Why it's wrong here

    Microsoft Entra Verified ID is a decentralized identity platform built on verifiable credentials, enabling users to prove claims (e.g., job title, education, or certification) via cryptographic attestations without central authority. It is designed for identity verification and authentication of claims, not for authenticating sign-in to applications or enforcing specific sign-in methods like FIDO2 or Windows Hello. Therefore, Verified ID cannot be used to require phishing-resistant authentication; that control belongs to Conditional Access policies and the authentication methods configuration.

  • ✓

    Conditional Access policies

    Why this is correct

    Conditional Access policies in Microsoft Entra ID are the correct enforcement mechanism because they can evaluate granular conditions—such as user, location, device compliance, and risk—and then apply grant controls that mandate specific authentication methods. Through the 'Authentication Strengths' feature or the 'Require authentication method' grant control, you can require FIDO2 security keys or Windows Hello for Business, both of which are hardware-backed and inherently phishing-resistant. This aligns with the requirement for rigorous phishing resistance, as these methods use asymmetric cryptography and are not susceptible to phishing attacks, unlike password-based or OTP-based methods.

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.