Courseiva

Implementing Passwordless Sign-In with Smartphone

Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)

⚠ Common exam trap

The trap here is that Microsoft Authenticator with notification is often marketed as 'passwordless' in casual contexts, but Microsoft's official documentation strictly classifies it as a multi-factor authentication method, not a passwordless one, because it still requires a password as the first factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Hello for Business

Windows Hello for Business is a passwordless authentication method that uses biometric or PIN-based credentials tied to a user's device, leveraging asymmetric key pairs to authenticate against Microsoft Entra ID without transmitting a password. It satisfies Microsoft's definition of passwordless because the private key never leaves the device, and authentication is performed via a cryptographic challenge-response protocol.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Hello for Business

    Why this is correct

    Windows Hello for Business is a passwordless sign-in method built into Windows devices that uses biometrics or a PIN tied to the user's device through an asymmetric key pair. The private key is protected by the TPM and never leaves the device, while the public key is registered in Microsoft Entra ID. This satisfies passwordless authentication because no shared secret is transmitted over the network, and it supports both cloud and hybrid deployments.

  • ✗

    Microsoft Authenticator with notification

    Why it's wrong here

    Microsoft Authenticator with notification is a multi-factor authentication (MFA) approval flow, not a passwordless sign-in. In this flow, the user first enters a password and then approves a push notification on their phone, so a shared secret is still required as the first factor. While Microsoft Authenticator can be configured for passwordless phone sign-in, the notification-specific mode still relies on the existing password and therefore does not meet the passwordless requirement.

  • ✗

    Password Hash Synchronization

    Why it's wrong here

    Password Hash Synchronization is a synchronization feature that replicates a hash of the user's password from on-premises Active Directory to Microsoft Entra ID. It is not an authentication method at all, and it certainly cannot provide passwordless authentication because it depends on storing and verifying password hashes. This option would be relevant to hybrid identity configuration, but it has no place in a passwordless authentication methods policy.

  • ✓

    FIDO2 security keys

    Why this is correct

    FIDO2 security keys are roaming, hardware-based authenticators that support passwordless authentication by using public-key cryptography. The user plugs in the key and completes a local gesture such as a fingerprint or PIN; the private key stays on the device and the public key is registered in Microsoft Entra ID. FIDO2 keys are phishing-resistant and align with the FIDO2/WebAuthn standards, making them a valid passwordless method for Entra ID organizations.

  • ✗

    SMS-based one-time passcode

    Why it's wrong here

    SMS-based one-time passcode sends a verification code to a mobile phone, which the user must enter after typing their username and password. This is a form of multi-factor authentication and requires the user to provide a shared secret, so it is not passwordless. Additionally, SMS is susceptible to SIM-swapping and phishing, which is why Microsoft recommends stronger, passwordless methods such as Windows Hello or FIDO2 keys.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.