SC-900 Practice Question: Describe the concepts of security, compliance, and identity
An organization wants to enable passwordless authentication for its users by using a mobile app. Which Microsoft Entra ID authentication method should they implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Authenticator (passwordless sign-in)
Microsoft Authenticator supports passwordless phone sign-in, allowing users to authenticate via app notification. FIDO2 security keys are hardware tokens. Windows Hello for Business uses biometrics. Temporary Access Pass is for initial setup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Temporary Access Pass
Why it's wrong here
Temporary Access Pass (TAP) is a time-limited credential designed to facilitate the initial setup of other strong authentication methods, including passwordless options, or to assist with account recovery. It functions as a temporary, single-use or short-duration password, allowing users to register a permanent passwordless method like Microsoft Authenticator or a FIDO2 key. TAP itself is not a persistent passwordless sign-in method but rather a bridge to enable them.
- ✗
Windows Hello for Business
Why it's wrong here
Windows Hello for Business (WHfB) enables strong, two-factor authentication directly from a user's Windows device, utilizing a combination of a biometric gesture (like facial recognition or fingerprint) or a PIN, along with the device itself. This method securely stores credentials on a Trusted Platform Module (TPM) chip within the device, providing enterprise-grade security. WHfB is inherently device-bound and does not involve a separate mobile application for the authentication process.
- ✗
FIDO2 security keys
Why it's wrong here
FIDO2 security keys are physical hardware devices that provide a highly secure and phishing-resistant form of passwordless authentication. These keys leverage public-key cryptography, where a private key is securely stored on the hardware device and never leaves it. Users authenticate by inserting the key into a USB port or using NFC, then typically confirming their presence by touching the key or entering a PIN directly on the device. They are distinct hardware tokens, not a mobile application.
- ✓
Microsoft Authenticator (passwordless sign-in)
Why this is correct
Microsoft Authenticator's passwordless sign-in feature allows users to authenticate to Azure AD-connected services by simply approving a notification on their registered mobile device, eliminating the need to type a password. This method leverages public-key cryptography, where the user's mobile phone acts as a secure authenticator, providing a convenient and phishing-resistant multi-factor authentication experience. It is a primary example of a passwordless method delivered through a dedicated mobile application.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Passwordless authentication
Passwordless authentication is a method of verifying a user's identity without requiring them to enter a password, using alternative factors like biometrics, hardware tokens, or one-time codes.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.