Courseiva
mediumMultiple Select

MS-102 Practice Question: Which TWO actions can an admin take to reduce the…

Which TWO actions can an admin take to reduce the number of passwords in use for end users?

⚠ Common exam trap

It's easy for candidates to confuse password reduction with password management improvements, such as SSPR or password policies, which do not actually decrease the number of passwords users must remember.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Windows Hello for Business

Windows Hello for Business replaces traditional password authentication with strong two-factor authentication tied to a user's device, using biometrics or a PIN. This directly reduces the reliance on passwords for end users by enabling passwordless sign-in to Windows devices and integrated applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enforce complex password policies

    Why it's wrong here

    Enforcing complex password policies in Microsoft Entra ID only increases the entropy and reset frequency of passwords; it forces users to create harder-to-guess strings but does not remove the password from any authentication flow. This option can actually increase failed logins and helpdesk reset volume, while the stated goal is to reduce reliance on passwords. A password policy is a security threshold, not a passwordless authentication method.

  • ✓

    Enable Windows Hello for Business

    Why this is correct

    Windows Hello for Business uses a device-bound asymmetric key pair protected by PIN or biometrics and authenticates the user to Microsoft Entra ID and on-premises resources without transmitting a password. When you register the device and enable the credential, Windows replaces the password prompt with the PIN/biometric gesture at sign-in to Windows, applications, and web resources. This directly reduces the number of password-based sign-ins because the user's key and gesture satisfy the authentication challenge.

  • ✗

    Configure self-service password reset

    Why it's wrong here

    Self-service password reset lets users set a new password through registered methods, but after the reset the account continues to use a password for all future sign-ins. It reduces helpdesk password reset tickets, but the authentication workflows still require an interactive password authentication from the user. Because self-service password reset is a recovery control for an existing password model, it does not reduce the count of password-based logins.

  • ✗

    Implement password hash sync

    Why it's wrong here

    Password hash synchronization synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, allowing users to use the same password for cloud authentication. It is an identity synchronization feature that makes password-based sign-in work consistently across environments, but it does not remove or replace password entry. On the contrary, enabling password hash sync often means users continue typing passwords against cloud services, and it is frequently a prerequisite for other Entra ID features rather than a passwordless solution.

  • ✓

    Deploy Microsoft Authenticator for passwordless sign-in

    Why this is correct

    Microsoft Authenticator passwordless sign-in, also called phone sign-in, registers the user's device and enables the Authenticator app to perform key-based authentication with Microsoft Entra ID. When enabled as an authentication method, users approve a number match and use a PIN or biometric inside the app, so the password is never entered on a sign-in screen. Administrators can enforce this by configuring the Authentication methods policy and Conditional Access, making it a direct passwordless option.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.