AZ-500 Secure identity and access Practice Question
Which TWO of the following are valid authentication methods in Microsoft Entra ID?
⚠ Common exam trap
Many exam-takers confuse identity infrastructure tools (like Microsoft Entra Connect) or workload identities (like Managed identities) with user authentication methods, leading them to select options that are related to identity but not valid for user sign-in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Temporary Access Pass
Temporary Access Pass (TAP) is a valid authentication method in Microsoft Entra ID that allows users to register passwordless methods (like FIDO2 or Microsoft Authenticator) by providing a time-limited passcode. It is designed for scenarios where users have forgotten their credentials or need to onboard new devices without a password. TAP is configured via the Authentication methods policy in Entra ID and supports both one-time use and configurable lifetimes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Temporary Access Pass
Why this is correct
Temporary Access Pass is a time-limited, admin-issued passcode that allows a user to sign in and complete first-time onboarding, such as registering phishing-resistant credentials like FIDO2 keys or Microsoft Authenticator. It is a first-class authentication method in Microsoft Entra ID, designed as a secure temporary credential that can be used once or for a short validity window, and it supports both primary and secondary authentication scenarios, including passwordless recovery when a user loses their existing methods.
- ✗
App registration
Why it's wrong here
App registration is not an authentication method; it is a configuration object in Microsoft Entra ID that defines an application's identity and the permissions it needs, enabling OAuth 2.0 and OpenID Connect flows. Registering an app only creates a service principal or application principal that acts as a non-user identity for programmatic access, and it is how apps authenticate to Entra ID, not how users authenticate. Users still rely on user-level authentication methods such as passwords, FIDO2 keys, or Temporary Access Passes to sign in to the tenant.
- ✓
FIDO2 security key
Why this is correct
FIDO2 security keys are a passwordless, standards-based authentication method supported by Microsoft Entra ID, using the WebAuthn protocol to cryptographically verify a user's presence and identity. The key stores a private key on a hardware device and challenges the user to complete a gesture (such as a touch or PIN) during sign-in, making it highly resistant to phishing and credential theft. It is a valid user-facing authentication method that can be registered via Temporary Access Pass during onboarding and is often used for privileged or high-security accounts.
- ✗
Managed identity
Why it's wrong here
Managed identity is not a user authentication method; it is an Microsoft Entra ID identity automatically assigned to Azure resources, such as VMs, functions, or app services, to authenticate to Azure services and key vaults without embedded credentials. It exists for workload or resource authentication to other Azure resources, representing the application's or service's identity rather than a human user's identity. Users cannot sign in using a managed identity, and it is not presented as an authentication option in the Entra ID sign-in experience.
- ✗
Microsoft Entra Connect
Why it's wrong here
Microsoft Entra Connect is a hybrid identity synchronization tool, not an authentication method. It is used to sync on-premises Active Directory objects to Microsoft Entra ID, enabling features like Password Hash Sync, Pass-through Authentication, and federation with AD FS. While it can configure the tenant's authentication settings for hybrid users, the tool itself does not serve as a credential or protocol that users provide at sign-in, so it is fundamentally a provisioning and sync service rather than an authentication mechanism.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.