AZ-305 Practice Question: Design identity, governance, and monitoring solutions
Your company uses Microsoft Entra ID for identity management. You need to ensure that users can access corporate resources without passwords while maintaining a high level of security. Which feature should you implement?
⚠ Common exam trap
Test-takers frequently confuse 'passwordless' with 'multifactor authentication' (MFA), assuming MFA alone removes the password requirement, but MFA still requires a password as the first factor unless explicitly combined with a passwordless method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passwordless authentication
Passwordless authentication (Option C) is correct because it allows users to access corporate resources without entering a password, using methods like Windows Hello for Business, FIDO2 security keys, or the Microsoft Authenticator app. This eliminates password-related risks (e.g., phishing, credential theft) while maintaining strong security through cryptographic key pairs or biometric verification, aligning with the requirement for both password-free access and high security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure AD B2C
Why it's wrong here
Azure AD B2C is a customer identity and access management (CIAM) product aimed at external consumers, not at your organization's internal employees. It lets you manage identity for customers who sign up for your apps—often with social or local accounts—but it does not replace or remove passwords for your workforce. Even if you configured a passwordless flow in B2C, that only affects the external customers using that directory, not the internal identities that reside in your Microsoft Entra ID tenant. Therefore, while B2C can support passwordless for external users, it is not the service you would use to eliminate passwords for internal users.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies are a policy engine in Microsoft Entra ID that evaluate signals such as user, device, location, and risk before allowing access. They can require MFA, block sign-in, or force device compliance, but they are not an authentication method themselves and do not remove the need for a password. A Conditional Access policy could require passwordless authentication as a grant control, but the user still needs an actual passwordless credential registered to satisfy that control. In essence, Conditional Access enforces the decision, but it is not the mechanism that lets a user prove their identity without a password.
- ✓
Passwordless authentication
Why this is correct
Passwordless authentication in Microsoft Entra ID lets users sign in without entering a password by using methods like Windows Hello for Business, FIDO2/WebAuthn security keys, or the Microsoft Authenticator app. These methods rely on asymmetric cryptography: the user's device or key securely stores a private key, and the server verifies a signed challenge using the corresponding public key. This eliminates common password attack vectors like phishing, credential stuffing, and password reuse. By replacing the password entirely with biometrics or a hardware-bound credential, it directly achieves the goal of password-free sign-in for internal users.
- ✗
Multifactor authentication (MFA)
Why it's wrong here
Multifactor authentication (MFA) strengthens security by requiring two or more factors—typically something you know (password), something you have (phone), and sometimes something you are (biometric). However, one of those factors is almost always still the password, so the user must type it and the password still exists as a credential and attack surface. MFA makes password theft less useful to an attacker, but it does not eliminate the password itself. Passwordless authentication, by contrast, replaces the password factor entirely with a possession-based or inherence-based factor, so no password is ever entered or stored for that sign-in.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.