AZ-500 Secure identity and access Practice Question
Your organization uses Microsoft Entra ID and wants to implement a secure passwordless authentication strategy. Which TWO solutions can be used natively in Microsoft Entra ID for passwordless sign-in?
⚠ Common exam trap
Candidates often confuse multi-factor authentication methods (like OTP or push notifications) with true passwordless authentication, which requires eliminating the password as a primary factor entirely, not just adding a second factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FIDO2 security keys
FIDO2 security keys are a native passwordless authentication method in Microsoft Entra ID, leveraging the WebAuthn standard to provide phishing-resistant, hardware-based credential verification. They eliminate passwords entirely by using public-key cryptography, where the private key never leaves the device, ensuring strong security against credential theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FIDO2 security keys
Why this is correct
FIDO2 security keys are a natively supported passwordless authentication method in Microsoft Entra ID. They use public-key cryptography via the WebAuthn/CTAP2 protocol, where the private key never leaves the hardware key and the public key is registered with the tenant. Because sign-in requires a user gesture (e.g., PIN or touch) and the key's cryptographic assertion is tied to the specific site, it is phishing-resistant and does not require a password.
- ✗
Microsoft Authenticator app with OTP
Why it's wrong here
The Microsoft Authenticator app's OTP mode generates time-based one-time passcodes, which are traditionally used only as an additional factor after entering a username and password. This means the user is still relying on a password as the primary authentication factor, so it cannot satisfy a passwordless sign-in scenario. Authenticator can be used for passwordless phone sign-in, but that is a different mode using cryptographic key exchange rather than OTP.
- ✗
Third-party password managers
Why it's wrong here
Third-party password managers act as a centralized vault for storing and autofilling existing passwords, but they do not eliminate the user's password from the authentication flow. Microsoft Entra ID's native passwordless methods rely on FIDO2, Windows Hello, or the Authenticator app's phone-sign-in mode, all of which use asymmetric cryptography rather than stored passwords. Password managers are not an authentication factor natively recognized by Entra ID for passwordless sign-in and may actually reduce security if they enable weak password reuse.
- ✓
Windows Hello for Business
Why this is correct
Windows Hello for Business is Microsoft's built-in passwordless credential for Windows devices, integrated directly into Microsoft Entra ID. It binds a public/private key pair to the user's device and uses a biometric (face/fingerprint) or PIN as the local gesture to unlock the private key. Unlike FIDO2 security keys, which are portable external devices, Windows Hello credentials are non-portable and tied to a specific PC, but both provide phishing-resistant, passwordless sign-in.
- ✗
Duo Security push notifications
Why it's wrong here
Duo Security push notifications are a third-party MFA solution, not a native Microsoft Entra ID passwordless authentication method. Push approvals typically occur after the user has already supplied a password, so the password still exists in the flow, and third-party push can be vulnerable to MFA fatigue attacks. Even if Duo integrates with Entra ID through federation or conditional access, it does not provide the same native, phishing-resistant passwordless experience as FIDO2 or Windows Hello for Business.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.