mediumMultiple Select
MS-102 Practice Question: Which TWO actions can an admin take to reduce the…
Which TWO actions can an admin take to reduce the number of passwords in use for end users?
⚠ Common exam trap
It's easy for candidates to confuse password reduction with password management improvements, such as SSPR or password policies, which do not actually decrease the number of passwords users must remember.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Windows Hello for Business
Windows Hello for Business replaces traditional password authentication with strong two-factor authentication tied to a user's device, using biometrics or a PIN. This directly reduces the reliance on passwords for end users by enabling passwordless sign-in to Windows devices and integrated applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforce complex password policies
Why it's wrong here
Enforcing complex password policies in Microsoft Entra ID only increases the entropy and reset frequency of passwords; it forces users to create harder-to-guess strings but does not remove the password from any authentication flow. This option can actually increase failed logins and helpdesk reset volume, while the stated goal is to reduce reliance on passwords. A password policy is a security threshold, not a passwordless authentication method.
- ✓
Enable Windows Hello for Business
Why this is correct
Windows Hello for Business uses a device-bound asymmetric key pair protected by PIN or biometrics and authenticates the user to Microsoft Entra ID and on-premises resources without transmitting a password. When you register the device and enable the credential, Windows replaces the password prompt with the PIN/biometric gesture at sign-in to Windows, applications, and web resources. This directly reduces the number of password-based sign-ins because the user's key and gesture satisfy the authentication challenge.
- ✗
Configure self-service password reset
Why it's wrong here
Self-service password reset lets users set a new password through registered methods, but after the reset the account continues to use a password for all future sign-ins. It reduces helpdesk password reset tickets, but the authentication workflows still require an interactive password authentication from the user. Because self-service password reset is a recovery control for an existing password model, it does not reduce the count of password-based logins.
- ✗
Implement password hash sync
Why it's wrong here
Password hash synchronization synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, allowing users to use the same password for cloud authentication. It is an identity synchronization feature that makes password-based sign-in work consistently across environments, but it does not remove or replace password entry. On the contrary, enabling password hash sync often means users continue typing passwords against cloud services, and it is frequently a prerequisite for other Entra ID features rather than a passwordless solution.
- ✓
Deploy Microsoft Authenticator for passwordless sign-in
Why this is correct
Microsoft Authenticator passwordless sign-in, also called phone sign-in, registers the user's device and enables the Authenticator app to perform key-based authentication with Microsoft Entra ID. When enabled as an authentication method, users approve a number match and use a PIN or biometric inside the app, so the password is never entered on a sign-in screen. Administrators can enforce this by configuring the Authentication methods policy and Conditional Access, making it a direct passwordless option.
Go deeper
Related to this question
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.