Which TWO of the following are valid authentication methods in Microsoft Entra ID that can be used as part of a Conditional Access policy? (Select two.)
Trap 1: SMS sign-in
SMS sign-in is not a primary authentication method in Microsoft Entra ID; SMS is used only to deliver one-time passcodes for multifactor authentication or self-service password reset. Conditional Access authentication strength does not list SMS as a method because it lacks cryptographic proof of possession and is susceptible to SIM-swap attacks. Therefore, SMS sign-in is not a valid authentication method.
Trap 2: Hardware OATH token
Hardware OATH tokens generate time-based one-time passwords and are registered as a secondary verification factor for MFA, not as a primary identity credential. In Conditional Access, an OATH token can only be required as a second factor after the user has already signed in with a primary method such as a password. Because the token does not identify the user on its own, it is not a valid authentication method.
Trap 3: FIDO2 security key
FIDO2 security keys are a passwordless authentication option, but Conditional Access does not expose them as a separate authentication strength method; they are grouped under the broader 'Passwordless' or phishing-resistant authentication strength. In Microsoft Entra ID, authentication strength bundles FIDO2 with Windows Hello for Business and certificate-based authentication rather than offering a distinct 'FIDO2' grant control. For this question, the valid methods are Password and Certificate-based authentication, so FIDO2 is incorrect.
- A
SMS sign-in
Why it fails: SMS sign-in is not a primary authentication method in Microsoft Entra ID; SMS is used only to deliver one-time passcodes for multifactor authentication or self-service password reset. Conditional Access authentication strength does not list SMS as a method because it lacks cryptographic proof of possession and is susceptible to SIM-swap attacks. Therefore, SMS sign-in is not a valid authentication method.
- B
Password
Password is a valid authentication method because Microsoft Entra ID treats it as a primary credential for cloud accounts, and Conditional Access authentication strength includes 'Password' as an allowed method. An authentication strength policy can explicitly permit password authentication, either on its own or as the first factor before MFA. Thus, Password is correct in the context of authentication methods.
- C
Certificate-based authentication
Certificate-based authentication (CBA) is a valid authentication method because it uses X.509 certificates stored on smart cards, USB tokens, or Windows Hello for Business, proving possession of the private key. Microsoft Entra ID supports CBA as a first-factor sign-in method and exposes it in Conditional Access authentication strength for phishing-resistant scenarios. Unlike SMS or OATH tokens, CBA can authenticate a user independently, making it a valid method.
- D
Hardware OATH token
Why it fails: Hardware OATH tokens generate time-based one-time passwords and are registered as a secondary verification factor for MFA, not as a primary identity credential. In Conditional Access, an OATH token can only be required as a second factor after the user has already signed in with a primary method such as a password. Because the token does not identify the user on its own, it is not a valid authentication method.
- E
FIDO2 security key
Why it fails: FIDO2 security keys are a passwordless authentication option, but Conditional Access does not expose them as a separate authentication strength method; they are grouped under the broader 'Passwordless' or phishing-resistant authentication strength. In Microsoft Entra ID, authentication strength bundles FIDO2 with Windows Hello for Business and certificate-based authentication rather than offering a distinct 'FIDO2' grant control. For this question, the valid methods are Password and Certificate-based authentication, so FIDO2 is incorrect.