A company uses Microsoft Entra ID and wants to enable passwordless authentication for all users to reduce phishing risks. Users are already using Microsoft Authenticator for MFA. Which passwordless method should you prioritize?
Microsoft Authenticator passwordless sign-in is the correct answer because it leverages the same mobile app already widely used for multi-factor authentication, requiring no extra hardware or PKI. The user simply enters their username and then approves a push notification on their phone, sometimes matching a number, while the phone's biometric or PIN validates the physical presence. This provides a phishing-resistant, strong authentication experience that works across Android and iOS, and because it reuses an existing app, user adoption is high and deployment is straightforward.
Why this answer
The organization already uses Microsoft Authenticator for MFA, making the transition to passwordless sign-in via Authenticator the most seamless and cost-effective path. This method leverages the existing app registration and push notification infrastructure, allowing users to authenticate with a biometric or PIN gesture without deploying additional hardware or certificates.
Exam trap
The trap here is that candidates may choose Windows Hello for Business (A) because it is a common passwordless option, but they overlook the requirement that it only works on Windows devices, not for all users across platforms.
How to eliminate wrong answers
Option A is wrong because Windows Hello for Business requires Windows devices and is not universally applicable to all users (e.g., mobile or non-Windows users). Option B is wrong because FIDO2 security keys require purchasing and distributing physical hardware, which adds cost and logistical overhead not justified when Authenticator is already deployed. Option C is wrong because certificate-based authentication requires a public key infrastructure (PKI) and certificate enrollment, which is more complex to deploy and manage than leveraging the existing Authenticator app.