Which TWO of the following are valid authentication methods in Microsoft Entra ID?
Trap 1: App registration
App registration is not an authentication method; it is a configuration object in Microsoft Entra ID that defines an application's identity and the permissions it needs, enabling OAuth 2.0 and OpenID Connect flows. Registering an app only creates a service principal or application principal that acts as a non-user identity for programmatic access, and it is how apps authenticate to Entra ID, not how users authenticate. Users still rely on user-level authentication methods such as passwords, FIDO2 keys, or Temporary Access Passes to sign in to the tenant.
Trap 2: Managed identity
Managed identity is not a user authentication method; it is an Microsoft Entra ID identity automatically assigned to Azure resources, such as VMs, functions, or app services, to authenticate to Azure services and key vaults without embedded credentials. It exists for workload or resource authentication to other Azure resources, representing the application's or service's identity rather than a human user's identity. Users cannot sign in using a managed identity, and it is not presented as an authentication option in the Entra ID sign-in experience.
Trap 3: Microsoft Entra Connect
Microsoft Entra Connect is a hybrid identity synchronization tool, not an authentication method. It is used to sync on-premises Active Directory objects to Microsoft Entra ID, enabling features like Password Hash Sync, Pass-through Authentication, and federation with AD FS. While it can configure the tenant's authentication settings for hybrid users, the tool itself does not serve as a credential or protocol that users provide at sign-in, so it is fundamentally a provisioning and sync service rather than an authentication mechanism.
- A
Temporary Access Pass
Temporary Access Pass is a time-limited, admin-issued passcode that allows a user to sign in and complete first-time onboarding, such as registering phishing-resistant credentials like FIDO2 keys or Microsoft Authenticator. It is a first-class authentication method in Microsoft Entra ID, designed as a secure temporary credential that can be used once or for a short validity window, and it supports both primary and secondary authentication scenarios, including passwordless recovery when a user loses their existing methods.
- B
App registration
Why it fails: App registration is not an authentication method; it is a configuration object in Microsoft Entra ID that defines an application's identity and the permissions it needs, enabling OAuth 2.0 and OpenID Connect flows. Registering an app only creates a service principal or application principal that acts as a non-user identity for programmatic access, and it is how apps authenticate to Entra ID, not how users authenticate. Users still rely on user-level authentication methods such as passwords, FIDO2 keys, or Temporary Access Passes to sign in to the tenant.
- C
FIDO2 security key
FIDO2 security keys are a passwordless, standards-based authentication method supported by Microsoft Entra ID, using the WebAuthn protocol to cryptographically verify a user's presence and identity. The key stores a private key on a hardware device and challenges the user to complete a gesture (such as a touch or PIN) during sign-in, making it highly resistant to phishing and credential theft. It is a valid user-facing authentication method that can be registered via Temporary Access Pass during onboarding and is often used for privileged or high-security accounts.
- D
Managed identity
Why it fails: Managed identity is not a user authentication method; it is an Microsoft Entra ID identity automatically assigned to Azure resources, such as VMs, functions, or app services, to authenticate to Azure services and key vaults without embedded credentials. It exists for workload or resource authentication to other Azure resources, representing the application's or service's identity rather than a human user's identity. Users cannot sign in using a managed identity, and it is not presented as an authentication option in the Entra ID sign-in experience.
- E
Microsoft Entra Connect
Why it fails: Microsoft Entra Connect is a hybrid identity synchronization tool, not an authentication method. It is used to sync on-premises Active Directory objects to Microsoft Entra ID, enabling features like Password Hash Sync, Pass-through Authentication, and federation with AD FS. While it can configure the tenant's authentication settings for hybrid users, the tool itself does not serve as a credential or protocol that users provide at sign-in, so it is fundamentally a provisioning and sync service rather than an authentication mechanism.