Tag: Multi-Factor Authentication (MFA)

Implement and configure authentication methods, including multifactor authentication (MFA) and passwordless (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
   --> Secure access to resources by using Microsoft Entra ID
      --> Implement and configure authentication methods, including multifactor authentication (MFA) and passwordless


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Authentication is the process of establishing that a user, application, device, or other identity is who or what it claims to be.

In Microsoft Entra ID, authentication is a foundational component of a broader Zero Trust security strategy. Strong authentication reduces the risk associated with stolen, guessed, or phished passwords and provides organizations with additional signals that can be used to establish identity.

For the SC-500 exam, this topic centers on understanding how to:

  • Configure authentication methods in Microsoft Entra ID
  • Implement multifactor authentication (MFA)
  • Implement passwordless authentication
  • Understand authentication method policies
  • Select appropriate authentication methods for different scenarios
  • Understand authentication strengths
  • Manage authentication method registration
  • Understand the relationship between authentication methods and Conditional Access
  • Troubleshoot authentication-related issues

A useful way to think about the topic is:

Authentication methods determine how an identity proves who it is; Conditional Access determines when stronger authentication should be required.


1. Authentication vs. Authorization

Before examining authentication methods, it is important to distinguish authentication from authorization.

Authentication

Authentication answers:

Who are you?

Examples:

  • Password
  • Microsoft Authenticator
  • FIDO2 security key
  • Windows Hello for Business
  • Certificate

Authorization

Authorization answers:

What are you allowed to do?

Examples:

  • Microsoft Entra roles
  • Azure RBAC
  • Application permissions
  • Group membership

Therefore:

Authentication → establishes identity

Authorization → determines access

A user could successfully authenticate but still be denied access because they don’t have the required permissions.


2. Authentication Factors

Multifactor authentication is based on combining different types of authentication factors.

The traditional categories are:

Something you know

Examples:

  • Password
  • PIN

Something you have

Examples:

  • Security key
  • Authenticator application
  • Hardware token

Something you are

Examples:

  • Fingerprint
  • Facial recognition

The security benefit of MFA comes from requiring multiple independent factors.

For example:

Password + Authenticator approval

is stronger than:

Password alone.


3. What Is Microsoft Entra Authentication?

Microsoft Entra ID provides authentication services for users and applications accessing Microsoft cloud resources and integrated applications.

Authentication can involve:

  1. A username or other identifier
  2. A credential or authentication method
  3. Additional authentication requirements
  4. Risk and contextual evaluation
  5. Token issuance
  6. Authorization to the requested resource

The authentication experience can vary depending on:

  • User
  • Application
  • Device
  • Location
  • Authentication method
  • Risk
  • Conditional Access policies

4. Microsoft Entra Authentication Methods

Microsoft Entra supports a variety of authentication methods.

Important methods for the SC-500 exam include:

  • Password
  • Microsoft Authenticator
  • Passkeys/FIDO2 security keys
  • Windows Hello for Business
  • Certificate-based authentication
  • Temporary Access Pass
  • OATH hardware/software tokens
  • SMS
  • Voice calls
  • Email OTP in supported scenarios

Not every method provides the same level of security.

For example:

A phishing-resistant authentication method generally provides stronger protection than SMS-based authentication.

Understanding those differences is more important than simply memorizing the list.


5. Password Authentication

Passwords are the traditional authentication mechanism.

They are easy to understand and widely supported, but they have significant weaknesses.

Passwords can be:

  • Guessed
  • Reused
  • Shared
  • Stolen
  • Phished
  • Captured through malware
  • Exposed through data breaches

This is one reason Microsoft promotes stronger authentication methods and passwordless authentication.


6. Passwordless Authentication

Passwordless authentication allows users to authenticate without entering a traditional account password.

Microsoft Entra passwordless methods include technologies such as:

  • Windows Hello for Business
  • FIDO2 security keys
  • Passkeys
  • Microsoft Authenticator passwordless phone sign-in

Passwordless authentication can improve security while also reducing password-related support issues.


7. Why Passwordless Is More Secure

Passwords are attractive targets because attackers can attempt to obtain them remotely.

Passwordless authentication can instead use:

  • Cryptographic keys
  • Device-bound credentials
  • Biometrics
  • PINs
  • Secure hardware

For example, with Windows Hello for Business, the user’s private key is protected on the device rather than being transmitted as a password.

The user may unlock the credential using:

  • PIN
  • Fingerprint
  • Facial recognition

The important distinction is:

The biometric or PIN unlocks the credential; it isn’t necessarily the credential itself.


8. Microsoft Authenticator

The Microsoft Authenticator app can support several authentication experiences.

It can be used for:

  • MFA
  • Passwordless authentication
  • Number matching
  • Push notifications
  • Account registration

For passwordless phone sign-in, the user authenticates through the Authenticator app rather than entering a traditional password.


9. Number Matching

Number matching is an important security improvement for Microsoft Authenticator push notifications.

Instead of simply asking the user:

“Approve this sign-in?”

the user is presented with a number during the sign-in process and must enter the matching number in the Authenticator application.

This helps reduce attacks in which users blindly approve unexpected authentication requests.

Example

The sign-in page displays:

42

The Authenticator app asks the user to enter:

42

The user enters the number and completes the authentication process.


10. Microsoft Authenticator Passwordless Authentication

With passwordless authentication using Microsoft Authenticator, the user doesn’t need to enter a password during the authentication experience.

A typical flow is:

  1. User enters their username.
  2. Microsoft Entra initiates authentication.
  3. The user receives an authentication request.
  4. The user interacts with Microsoft Authenticator.
  5. Number matching may be required.
  6. The user completes the authentication.
  7. Authentication succeeds.

This can provide a more secure and convenient alternative to password-based authentication.


11. FIDO2 Security Keys

FIDO2 security keys are physical authentication devices that use public-key cryptography.

Examples include USB, NFC, or other compatible security keys.

The key contains cryptographic credentials that can be used to authenticate the user.

A major advantage is:

FIDO2 authentication is designed to resist phishing.

The authentication process is cryptographically bound to the legitimate website or service.


12. Passkeys

Passkeys are another passwordless authentication technology based on public-key cryptography.

Passkeys can be stored on supported devices or credential managers and can use local user verification such as:

  • Biometrics
  • Device PIN
  • Other supported local unlock mechanisms

The private key remains protected by the credential provider while the service uses the corresponding public key.

Passkeys are based on the FIDO authentication model.


13. Windows Hello for Business

Windows Hello for Business provides passwordless authentication for Windows devices.

It uses asymmetric cryptography.

A private key is protected on the user’s device, while the corresponding public key is registered with the identity provider.

The user typically unlocks the credential using:

  • PIN
  • Fingerprint
  • Facial recognition

Windows Hello for Business is particularly useful for organizations with managed Windows devices.


14. Windows Hello for Business vs. Microsoft Authenticator

These are both passwordless approaches, but they serve different scenarios.

FeatureWindows Hello for BusinessMicrosoft Authenticator
Primary environmentWindows devicesMobile devices
PasswordlessYesYes
Local device credentialYesUses mobile authentication
BiometricsSupportedSupported by device
PINSupportedDevice/app authentication mechanisms
Enterprise Windows integrationStrongLess device-centric
Typical useManaged Windows workstationMobile/passwordless sign-in

Exam clue

If the scenario emphasizes:

Windows device + enterprise credentials + PIN/biometrics

Think:

Windows Hello for Business

If it emphasizes:

Mobile phone + passwordless authentication

Think:

Microsoft Authenticator


15. Certificate-Based Authentication

Microsoft Entra also supports certificate-based authentication (CBA).

With CBA, the user authenticates using a certificate rather than a traditional password.

This can be useful in organizations that already have a public key infrastructure (PKI).

Certificate-based authentication can provide strong authentication and can be incorporated into authentication-strength requirements.


16. Temporary Access Pass

A Temporary Access Pass (TAP) is a time-limited passcode that can be used to bootstrap authentication.

It is particularly useful when a user needs to register a passwordless authentication method but doesn’t yet have another strong authentication method available.

For example:

  1. New employee receives a Temporary Access Pass.
  2. Employee uses TAP to authenticate.
  3. Employee registers Microsoft Authenticator or another passwordless method.
  4. TAP expires.

This makes TAP particularly useful for:

  • New-user onboarding
  • Passwordless registration
  • Recovery scenarios
  • Registering authentication methods

Important

A TAP is temporary.

It is not intended to replace a user’s long-term authentication method.


17. Multifactor Authentication

Multifactor authentication (MFA) requires users to satisfy authentication requirements involving multiple factors.

For example:

Password + Authenticator

or:

Password + FIDO2 security key

MFA provides additional protection when one authentication factor is compromised.


18. Microsoft Entra MFA

Microsoft Entra MFA can be required using Conditional Access and other supported authentication mechanisms.

A common configuration is:

User signs in → Conditional Access evaluates conditions → MFA is required → User completes MFA → Access continues

This is different from configuring the authentication method itself.

For example:

Authentication method

Microsoft Authenticator is enabled.

Conditional Access

The organization requires MFA when users access sensitive applications.

Therefore:

Authentication methods provide the mechanisms; Conditional Access can require them based on context.


19. Authentication Method Policies

Administrators can control which authentication methods users are permitted to register and use.

Authentication method policies help organizations:

  • Enable or disable methods
  • Define who can use particular methods
  • Configure method-specific settings
  • Manage authentication-method availability

This is important because simply having an authentication method available doesn’t mean every user should be permitted to use it.


20. Authentication Method Registration

Users need to register their authentication methods before they can use many of them.

For example, a user may need to register:

  • Microsoft Authenticator
  • FIDO2 security key
  • Phone number
  • Other supported methods

Microsoft Entra provides registration experiences that help users configure authentication methods.

Administrators should consider:

  • Which users can register
  • Which methods they can register
  • How registration is secured
  • How users recover access
  • Which methods satisfy organizational security requirements

21. Authentication Registration Policy

Organizations can control which authentication methods users are encouraged or required to register.

For example, an organization could prioritize:

Microsoft Authenticator

over:

SMS

for MFA registration.

This helps organizations gradually move users toward stronger authentication methods.


22. Self-Service Password Reset

Although passwordless authentication reduces reliance on passwords, organizations may still have users who authenticate with passwords.

Self-Service Password Reset (SSPR) allows users to reset their passwords without requiring help-desk intervention.

SSPR can use registered authentication methods to verify the user’s identity.

For example:

User forgets password → verifies identity → creates new password.


23. SSPR and MFA Are Related but Different

This distinction is important.

MFA

Protects authentication to resources.

SSPR

Helps users reset or change passwords.

They can use some of the same authentication methods, but they solve different problems.


24. Authentication Strength

Authentication strength allows an organization to specify the type or strength of authentication required for access.

This is particularly useful with Conditional Access.

Instead of saying:

Require MFA.

an organization can say:

Require a phishing-resistant authentication method.

This provides greater control over which authentication methods satisfy the policy.


25. Built-In Authentication Strengths

Microsoft Entra provides predefined authentication-strength configurations, including concepts such as:

  • Multifactor authentication
  • Passwordless MFA
  • Phishing-resistant MFA

These allow organizations to align authentication requirements with the sensitivity of the resource.


26. Phishing-Resistant Authentication

Phishing-resistant authentication is designed to prevent attackers from successfully using stolen authentication information on a fraudulent website.

Examples include:

  • FIDO2 security keys
  • Passkeys
  • Windows Hello for Business
  • Certain certificate-based authentication scenarios

By contrast, methods such as SMS codes can potentially be intercepted or socially engineered.

Exam clue

If the question says:

“The organization requires an authentication method that is resistant to phishing.”

Look for:

FIDO2 / passkeys / Windows Hello for Business / appropriate phishing-resistant authentication strength

rather than simply:

SMS MFA


27. Authentication Methods and Conditional Access

These two concepts work together.

Authentication methods

Determine what authentication mechanisms are available.

Conditional Access

Determines when a particular level or type of authentication is required.

For example:

Authentication method policy

Enable FIDO2 for administrators.

Conditional Access

Require phishing-resistant MFA for administrators accessing privileged resources.

This combination provides much stronger control than simply enabling authentication methods globally.


28. Example: Protect Administrators

Suppose an organization wants to protect privileged administrators.

A good design could be:

Step 1

Enable a strong authentication method such as FIDO2 or Windows Hello for Business.

Step 2

Ensure administrators can register the method.

Step 3

Create a Conditional Access policy targeting privileged administrators.

Step 4

Require an appropriate authentication strength.

Step 5

Monitor authentication activity.

The result is stronger protection for high-value identities.


29. Example: Passwordless Deployment

A company wants to move users away from passwords.

A possible deployment strategy is:

Phase 1

Enable passwordless methods.

Phase 2

Allow users to register them.

Phase 3

Use Temporary Access Pass to help users bootstrap registration.

Phase 4

Train users.

Phase 5

Use Conditional Access to require stronger authentication for appropriate applications.

Phase 6

Gradually reduce reliance on passwords.

This staged approach reduces deployment risk.


30. Authentication Method Selection

Choosing the right authentication method depends on the scenario.

ScenarioStrong candidate
Managed Windows workstationWindows Hello for Business
Phishing-resistant hardware authenticationFIDO2 security key
Passwordless mobile authenticationMicrosoft Authenticator
Passwordless modern authenticationPasskey
Existing PKI infrastructureCertificate-based authentication
Bootstrap passwordless registrationTemporary Access Pass
Legacy/simple MFA scenarioSMS or voice, where supported
Strong privileged-user authenticationPhishing-resistant authentication

The strongest option isn’t always the easiest to deploy, so security requirements and operational considerations must both be evaluated.


31. Why SMS Is Weaker

SMS-based authentication can provide an additional authentication factor, but it has known security limitations.

Potential threats include:

  • SIM swapping
  • Social engineering
  • Phone-number takeover
  • Interception
  • Phishing

Therefore:

SMS can be better than password-only authentication, but it generally isn’t the preferred option when stronger phishing-resistant methods are available.


32. Authentication Method vs. Authentication Strength

This distinction can appear in scenario questions.

Authentication method

Examples:

  • FIDO2
  • Authenticator
  • SMS
  • Windows Hello

Authentication strength

Describes the security requirements that an authentication method or combination must satisfy.

For example:

Conditional Access requires phishing-resistant MFA.

The administrator then needs to configure users with authentication methods capable of satisfying that requirement.


33. Passwordless Does Not Mean “No User Verification”

Passwordless authentication doesn’t mean that the user doesn’t have to prove control of the credential.

For example:

Windows Hello for Business might require:

PIN or biometric verification.

FIDO2 might require:

Security-key interaction and/or PIN/biometric verification.

Passkeys may use:

Device-based user verification.

The key difference is:

The user isn’t authenticating by transmitting a traditional password.


34. Common Authentication Security Principles

A secure authentication strategy should:

  • Prefer phishing-resistant authentication
  • Reduce password dependency
  • Use MFA for appropriate scenarios
  • Protect privileged accounts more strongly
  • Minimize weaker authentication methods
  • Control authentication-method registration
  • Monitor authentication activity
  • Provide secure recovery mechanisms
  • Use Conditional Access for contextual requirements
  • Regularly review authentication methods

35. Common Exam Traps

Trap 1: MFA = passwordless

False.

MFA can use a password as one of its factors.

Example:

Password + Authenticator = MFA

Passwordless authentication doesn’t use a traditional password.


Trap 2: Authentication method = Conditional Access

False.

Authentication methods define available authentication mechanisms.

Conditional Access determines when authentication requirements should apply.


Trap 3: SMS is phishing-resistant

False.

SMS is not generally considered a phishing-resistant authentication method.


Trap 4: TAP is a permanent credential

False.

A Temporary Access Pass is designed to be temporary and is commonly used to bootstrap authentication-method registration.


Trap 5: Biometrics are always the authentication credential

Not necessarily.

With Windows Hello for Business, for example, biometric verification can unlock a credential stored on the device.


Trap 6: SSPR is the same as MFA

False.

SSPR addresses password reset.

MFA strengthens authentication.


Trap 7: Passwordless means no authentication

False.

Passwordless authentication still strongly authenticates the user; it simply doesn’t rely on a traditional password.


Trap 8: Enabling an authentication method automatically requires users to use it

False.

Enabling a method and requiring a method are separate concepts.

Authentication-method configuration controls availability.

Conditional Access and authentication-strength requirements can control when stronger authentication is required.


36. Recommended Authentication Strategy

A mature Microsoft Entra authentication strategy can look like this:

Tier 1 — Eliminate unnecessary passwords

Adopt passwordless authentication where practical.

Tier 2 — Protect users with MFA

Require MFA for appropriate applications and scenarios.

Tier 3 — Protect privileged identities

Require stronger, preferably phishing-resistant authentication for administrators.

Tier 4 — Use Conditional Access

Apply authentication requirements based on:

  • User
  • Resource
  • Device
  • Location
  • Risk
  • Application
  • Other contextual signals

Tier 5 — Monitor

Review authentication activity and investigate suspicious behavior.


37. SC-500 Quick Reference

ConceptRemember
AuthenticationProves identity
AuthorizationDetermines permissions
MFAUses multiple authentication factors
PasswordlessAuthenticates without traditional password
Microsoft AuthenticatorSupports MFA and passwordless authentication
Number matchingHelps defend against accidental MFA approval
FIDO2Strong, phishing-resistant authentication
PasskeysPasswordless, public-key-based authentication
Windows Hello for BusinessPasswordless Windows authentication
Certificate-based authenticationUses certificates instead of passwords
Temporary Access PassTemporary bootstrap credential
SSPREnables user password reset
Authentication methodsDefine available authentication mechanisms
Authentication strengthDefines required authentication security level
Conditional AccessDetermines when access/authentication requirements apply
Phishing-resistant authenticationDesigned to resist credential phishing
SMSWeaker than modern phishing-resistant methods
RegistrationEstablishes the user’s authentication method
Privileged usersShould receive stronger authentication protections

Practice Exam Questions

Question 1

An organization wants users to authenticate to Microsoft Entra ID without entering a traditional password. Users have managed Windows 11 devices and can use a PIN or biometric authentication.

Which authentication method is the best fit?

A. SMS authentication

B. Windows Hello for Business

C. Voice call authentication

D. Password hash synchronization

Answer: B

Explanation: Windows Hello for Business provides passwordless authentication for Windows devices and can use a PIN or biometric gesture to unlock the user’s credential. The private key is protected on the device.


Question 2

A security administrator wants to protect privileged administrators against phishing attacks. The organization wants administrators to use hardware security keys based on public-key cryptography.

Which authentication method should the administrator implement?

A. SMS

B. Voice call

C. FIDO2 security keys

D. Email OTP

Answer: C

Explanation: FIDO2 security keys use public-key cryptography and are designed to provide phishing-resistant authentication. They are particularly appropriate for protecting privileged identities.


Question 3

An organization is deploying passwordless authentication. Many users do not yet have a registered passwordless authentication method.

The administrator needs a temporary authentication mechanism that users can use to bootstrap registration of a passwordless method.

What should the administrator use?

A. Temporary Access Pass

B. Azure RBAC

C. Security Defaults

D. Access reviews

Answer: A

Explanation: A Temporary Access Pass (TAP) is a time-limited credential that can be used to bootstrap authentication-method registration, including passwordless methods. It isn’t intended to be a permanent authentication credential.


Question 4

An organization currently uses SMS-based MFA but wants to provide administrators with authentication that is resistant to phishing.

Which approach should the organization take?

A. Require longer SMS codes

B. Increase the SMS message frequency

C. Require password changes every 30 days

D. Require a phishing-resistant authentication method

Answer: D

Explanation: SMS provides an additional factor but isn’t considered phishing-resistant. The organization should use a phishing-resistant method such as FIDO2, passkeys, Windows Hello for Business, or another method that satisfies the required authentication strength.


Question 5

An administrator wants to require MFA whenever users access a sensitive application. The organization has already enabled Microsoft Authenticator as an authentication method.

Which capability should the administrator use to determine when users must perform MFA?

A. Microsoft Entra Conditional Access

B. Azure Resource Manager locks

C. Azure Policy

D. Azure Storage firewall

Answer: A

Explanation: Authentication-method configuration makes Microsoft Authenticator available. Conditional Access can determine when MFA must be performed based on users, resources, conditions, and other contextual signals.


Question 6

A user has configured Windows Hello for Business with facial recognition. Which statement best describes how the biometric is used?

A. The user’s facial image is transmitted to Microsoft Entra ID as the password

B. The biometric replaces all cryptographic credentials

C. The biometric can be used to unlock the credential on the device

D. The biometric is stored as the user’s Microsoft Entra password

Answer: C

Explanation: Windows Hello for Business uses asymmetric cryptography. The local PIN or biometric can unlock the credential on the device. The biometric isn’t simply transmitted to Microsoft Entra ID as a password.


Question 7

An organization wants users to be able to reset forgotten passwords without contacting the help desk. The organization wants users to verify their identity using registered authentication methods.

Which feature should be implemented?

A. Microsoft Entra Privileged Identity Management

B. Self-Service Password Reset

C. Azure Policy

D. Microsoft Defender for Cloud

Answer: B

Explanation: Self-Service Password Reset (SSPR) allows users to reset their passwords after satisfying the configured identity-verification requirements. MFA and SSPR are related but serve different purposes.


Question 8

An organization wants to require administrators to use authentication that meets a phishing-resistant authentication requirement. The administrator wants Conditional Access to enforce this requirement rather than simply requiring generic MFA.

Which capability should be configured?

A. Named locations

B. Authentication strength

C. Device compliance

D. Sign-in frequency

Answer: B

Explanation: Authentication strength allows Conditional Access to require a specific level or type of authentication, including phishing-resistant authentication. This is more precise than simply selecting a generic “Require MFA” control.


Question 9

An organization enables Microsoft Authenticator push notifications. The security team wants to reduce the risk that users will accidentally approve fraudulent authentication requests.

Which capability should be used?

A. Number matching

B. Password expiration

C. Azure Resource Locks

D. SSPR

Answer: A

Explanation: Number matching requires the user to enter the number displayed during the sign-in process into the Authenticator application. This helps reduce accidental approval of unexpected authentication requests.


Question 10

An organization has enabled several authentication methods in Microsoft Entra ID. The security team wants to ensure that users can register only authentication methods approved for their particular group.

Which capability should the administrator configure?

A. Azure Policy

B. Azure Firewall

C. Authentication method policies

D. Resource locks

Answer: C

Explanation: Authentication method policies allow administrators to control which authentication methods are available to users and groups and configure method-specific settings. This allows organizations to manage authentication-method availability rather than simply enabling every method for everyone.


Final Exam Takeaways

For this SC-500 objective, the most important mental model is:

Authentication methods define how users authenticate. Conditional Access determines when stronger authentication is required. Authentication strength determines how strong that authentication must be.

And remember these high-value distinctions:

  • MFA can include a password; passwordless does not use a traditional password.
  • FIDO2, passkeys, and Windows Hello for Business are important passwordless/phishing-resistant technologies.
  • Microsoft Authenticator supports both MFA and passwordless authentication.
  • Number matching helps protect against unwanted Authenticator approvals.
  • Temporary Access Pass is primarily a temporary bootstrap mechanism.
  • SSPR is for password reset, not simply for enforcing MFA.
  • Authentication-method policies control method availability and configuration.
  • Authentication strength lets Conditional Access require a particular level/type of authentication.
  • Conditional Access determines when authentication requirements apply.
  • SMS MFA is weaker than modern phishing-resistant authentication.
  • Biometrics/PINs can unlock a device-bound credential rather than being transmitted as a password.
  • Privileged identities deserve stronger authentication requirements than ordinary users.

A useful exam formula is:

Available method → Registration → Conditional Access → Authentication strength → Authentication → Access.


Go to the SC-500 Exam Prep Hub main page