SC-900 Describe the capabilities of Microsoft Entra Practice Question
You are an identity consultant for a mid-sized company with 5,000 employees. They use Microsoft Entra ID P1 and Microsoft Intune for device management. The company wants to implement passwordless authentication for all employees to improve security and user experience. Currently, users sign in with username and password plus MFA via the Microsoft Authenticator app. The company has a mix of Windows 10/11 devices (both domain-joined and Microsoft Entra joined) and iOS/Android mobile devices. They want to support passwordless sign-in on all platforms. The CTO is concerned about cost and wants to minimize additional licensing. Which passwordless method should you recommend?
⚠ Common exam trap
Many candidates assume Windows Hello for Business is the only Microsoft passwordless solution for Windows devices, overlooking that the Microsoft Authenticator app can provide passwordless sign-in across all platforms (Windows, iOS, Android) without additional licensing or hardware costs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Microsoft Authenticator app for passwordless sign-in
The Microsoft Authenticator app supports passwordless sign-in using phone-based authentication, which works on both iOS and Android devices and can be used to sign into Windows 10/11 devices via the 'Sign in with phone' feature. This method leverages existing Microsoft Entra ID P1 licensing without requiring additional costs, as it is included with the current P1 license. It provides a seamless user experience by eliminating the need for hardware tokens or additional infrastructure, aligning with the CTO's cost-minimization goal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Windows Hello for Business for all devices
Why it's wrong here
Enabling Windows Hello for Business (WHfB) is not a suitable solution for "all devices" because it is primarily designed for Windows 10/11 devices joined to Azure AD or hybrid AD. WHfB relies on device-bound biometrics or PINs, which are not natively supported or applicable for non-Windows platforms like iOS or Android mobile devices. Therefore, it cannot provide a universal passwordless experience across a diverse device ecosystem, leaving a significant portion of users without the desired functionality.
- ✗
Deploy FIDO2 security keys to all employees
Why it's wrong here
Deploying FIDO2 security keys to all employees, while offering strong passwordless authentication, presents significant logistical and financial challenges for a mid-sized company. These hardware keys require procurement, distribution, and ongoing management, incurring substantial upfront costs and potential replacement expenses. Furthermore, ensuring all employees consistently carry and use a physical key across various devices, including mobile phones where they might not be natively integrated, can complicate user experience and adoption.
- ✗
Implement SMS-based one-time passcodes
Why it's wrong here
Implementing SMS-based one-time passcodes (OTP) does not achieve a truly passwordless sign-in experience. While SMS OTP enhances security by adding a second factor, it still mandates that users first enter their traditional password as the primary credential. The goal of passwordless authentication is to entirely eliminate the need for a password, replacing it with a stronger, often biometric or device-bound, method from the initial sign-in prompt.
- ✓
Use the Microsoft Authenticator app for passwordless sign-in
Why this is correct
The Microsoft Authenticator app offers a highly effective and cost-efficient solution for passwordless sign-in across a wide range of devices, including iOS, Android, and Windows. It leverages existing smartphone hardware to provide a secure, push-notification-based or number-matching authentication method, eliminating the need for users to type a password. This approach minimizes additional hardware costs, simplifies deployment, and enhances user convenience and security by removing the weakest link in traditional authentication.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.