Courseiva
easyMultiple ChoiceObjective-mapped

MD-102 Practice Question: Implementing Windows Hello for Business and wants…

A company is implementing Windows Hello for Business and wants to use certificate-based authentication. They have an on-premises Active Directory and are using Azure AD Connect for hybrid identity. Which prerequisites must be met to support certificate-based Windows Hello for Business?

⚠ Common exam trap

A common mix-up: candidates confuse the prerequisites for certificate-based Windows Hello for Business with those for passwordless sign-in or MFA, mistakenly thinking that the Authenticator app or Conditional Access policies are required, when in fact the core requirement is an enterprise CA and the correct device join state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An enterprise certification authority (CA) must be deployed and all devices must be Azure AD joined or hybrid Azure AD joined.

Certificate-based Windows Hello for Business requires an enterprise PKI to issue and validate certificates for authentication. Devices must be Azure AD joined or hybrid Azure AD joined to enroll these certificates and support the certificate trust model. On-premises Active Directory and Azure AD Connect provide the hybrid identity foundation, but the CA and appropriate device join state are the critical prerequisites.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • All users must have the Microsoft Authenticator app installed.

    Why it's wrong here

    Authenticator is not required for certificate-based Windows Hello for Business.

  • Conditional Access policies must be configured to require Windows Hello for Business.

    Why it's wrong here

    Conditional Access is not a prerequisite for deploying Windows Hello for Business.

  • An enterprise certification authority (CA) must be deployed and all devices must be Azure AD joined or hybrid Azure AD joined.

    Why this is correct

    Certificate-based Windows Hello requires a CA and hybrid or Azure AD joined devices.

  • All users must be configured for passwordless sign-in.

    Why it's wrong here

    Passwordless is a feature, not a prerequisite.

About these practice questions

Courseiva writes every MD-102 question from scratch — 942 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.