Courseiva

Implementing Passwordless Sign-In with Smartphone

Your organization uses Microsoft Entra ID. You need to implement a solution that allows users to sign in without a password using their smartphone. Which TWO authentication methods can be used?

Quick Answer

The answer is the Microsoft Authenticator app and FIDO2 security keys. These two passwordless authentication methods for smartphone use are correct because Microsoft Entra ID supports both for eliminating passwords: the Authenticator app enables phone sign-in through push notifications or number matching on the smartphone, while FIDO2 keys leverage hardware-based public/private key cryptography, often connecting via USB or NFC to the device. On the MS-102 exam, this question tests your understanding of which Entra ID passwordless options are specifically tied to smartphone usage—a common trap is confusing Windows Hello for Business (which is device-bound, not smartphone-based) with these two methods. Remember that the Authenticator app is software-based on the phone itself, whereas FIDO2 keys are external hardware that can interact with the smartphone through NFC. A helpful memory tip: "App and Key—both password-free, both phone-friendly."

⚠ Common exam trap

A common mix-up: candidates confuse SMS verification codes (a multi-factor authentication method) with a primary passwordless authentication method, but SMS codes require a password first and are not passwordless.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Authenticator app (phone sign-in)

The Microsoft Authenticator app supports phone sign-in, which allows users to authenticate by approving a notification or entering a number displayed on the screen, eliminating the need for a password. FIDO2 security keys enable passwordless authentication using hardware-based public/private key cryptography, meeting the requirement for smartphone-based sign-in when the key is connected via USB or NFC. Both methods are supported by Microsoft Entra ID for passwordless authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Temporary Access Pass

    Why it's wrong here

    Temporary Access Pass is for recovery, not passwordless.

  • Windows Hello for Business

    Why it's wrong here

    Windows Hello requires a Windows device.

  • Text message (SMS) verification code

    Why it's wrong here

    SMS is not passwordless; it's a second factor.

  • Microsoft Authenticator app (phone sign-in)

    Why this is correct

    Authenticator app supports passwordless sign-in.

  • FIDO2 security keys

    Why this is correct

    FIDO2 keys provide passwordless authentication.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)

easy
  • A.Windows Hello for Business
  • B.Microsoft Authenticator with notification
  • C.Password Hash Synchronization
  • D.FIDO2 security keys
  • E.SMS-based one-time passcode

Why A: Windows Hello for Business is a passwordless authentication method that uses biometric or PIN-based credentials tied to a user's device, leveraging asymmetric key pairs to authenticate against Microsoft Entra ID without transmitting a password. It satisfies Microsoft's definition of passwordless because the private key never leaves the device, and authentication is performed via a cryptographic challenge-response protocol.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.