Implementing Passwordless Sign-In with Smartphone
Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)
⚠ Common exam trap
The trap here is that Microsoft Authenticator with notification is often marketed as 'passwordless' in casual contexts, but Microsoft's official documentation strictly classifies it as a multi-factor authentication method, not a passwordless one, because it still requires a password as the first factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Hello for Business
Windows Hello for Business is a passwordless authentication method that uses biometric or PIN-based credentials tied to a user's device, leveraging asymmetric key pairs to authenticate against Microsoft Entra ID without transmitting a password. It satisfies Microsoft's definition of passwordless because the private key never leaves the device, and authentication is performed via a cryptographic challenge-response protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Hello for Business
Why this is correct
Windows Hello for Business is a passwordless sign-in method built into Windows devices that uses biometrics or a PIN tied to the user's device through an asymmetric key pair. The private key is protected by the TPM and never leaves the device, while the public key is registered in Microsoft Entra ID. This satisfies passwordless authentication because no shared secret is transmitted over the network, and it supports both cloud and hybrid deployments.
- ✗
Microsoft Authenticator with notification
Why it's wrong here
Microsoft Authenticator with notification is a multi-factor authentication (MFA) approval flow, not a passwordless sign-in. In this flow, the user first enters a password and then approves a push notification on their phone, so a shared secret is still required as the first factor. While Microsoft Authenticator can be configured for passwordless phone sign-in, the notification-specific mode still relies on the existing password and therefore does not meet the passwordless requirement.
- ✗
Password Hash Synchronization
Why it's wrong here
Password Hash Synchronization is a synchronization feature that replicates a hash of the user's password from on-premises Active Directory to Microsoft Entra ID. It is not an authentication method at all, and it certainly cannot provide passwordless authentication because it depends on storing and verifying password hashes. This option would be relevant to hybrid identity configuration, but it has no place in a passwordless authentication methods policy.
- ✓
FIDO2 security keys
Why this is correct
FIDO2 security keys are roaming, hardware-based authenticators that support passwordless authentication by using public-key cryptography. The user plugs in the key and completes a local gesture such as a fingerprint or PIN; the private key stays on the device and the public key is registered in Microsoft Entra ID. FIDO2 keys are phishing-resistant and align with the FIDO2/WebAuthn standards, making them a valid passwordless method for Entra ID organizations.
- ✗
SMS-based one-time passcode
Why it's wrong here
SMS-based one-time passcode sends a verification code to a mobile phone, which the user must enter after typing their username and password. This is a form of multi-factor authentication and requires the user to provide a shared secret, so it is not passwordless. Additionally, SMS is susceptible to SIM-swapping and phishing, which is why Microsoft recommends stronger, passwordless methods such as Windows Hello or FIDO2 keys.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.