Implementing Passwordless Sign-In with Smartphone
Your organization uses Microsoft Entra ID. You need to implement a solution that allows users to sign in without a password using their smartphone. Which TWO authentication methods can be used?
Quick Answer
The answer is the Microsoft Authenticator app and FIDO2 security keys. These two passwordless authentication methods for smartphone use are correct because Microsoft Entra ID supports both for eliminating passwords: the Authenticator app enables phone sign-in through push notifications or number matching on the smartphone, while FIDO2 keys leverage hardware-based public/private key cryptography, often connecting via USB or NFC to the device. On the MS-102 exam, this question tests your understanding of which Entra ID passwordless options are specifically tied to smartphone usage—a common trap is confusing Windows Hello for Business (which is device-bound, not smartphone-based) with these two methods. Remember that the Authenticator app is software-based on the phone itself, whereas FIDO2 keys are external hardware that can interact with the smartphone through NFC. A helpful memory tip: "App and Key—both password-free, both phone-friendly."
⚠ Common exam trap
A common mix-up: candidates confuse SMS verification codes (a multi-factor authentication method) with a primary passwordless authentication method, but SMS codes require a password first and are not passwordless.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Authenticator app (phone sign-in)
The Microsoft Authenticator app supports phone sign-in, which allows users to authenticate by approving a notification or entering a number displayed on the screen, eliminating the need for a password. FIDO2 security keys enable passwordless authentication using hardware-based public/private key cryptography, meeting the requirement for smartphone-based sign-in when the key is connected via USB or NFC. Both methods are supported by Microsoft Entra ID for passwordless authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Temporary Access Pass
Why it's wrong here
Temporary Access Pass is for recovery, not passwordless.
- ✗
Windows Hello for Business
Why it's wrong here
Windows Hello requires a Windows device.
- ✗
Text message (SMS) verification code
Why it's wrong here
SMS is not passwordless; it's a second factor.
- ✓
Microsoft Authenticator app (phone sign-in)
Why this is correct
Authenticator app supports passwordless sign-in.
- ✓
FIDO2 security keys
Why this is correct
FIDO2 keys provide passwordless authentication.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Entra ID and wants to implement a passwordless authentication strategy. Which TWO authentication methods are considered passwordless by Microsoft? (Choose two.)
easy- ✓ A.Windows Hello for Business
- B.Microsoft Authenticator with notification
- C.Password Hash Synchronization
- ✓ D.FIDO2 security keys
- E.SMS-based one-time passcode
Why A: Windows Hello for Business is a passwordless authentication method that uses biometric or PIN-based credentials tied to a user's device, leveraging asymmetric key pairs to authenticate against Microsoft Entra ID without transmitting a password. It satisfies Microsoft's definition of passwordless because the private key never leaves the device, and authentication is performed via a cryptographic challenge-response protocol.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.