Subdomain 1.2: Understand the Microsoft 365 security principles
1.A manufacturing company prohibits employees from bringing mobile phones onto the factory floor. Which authentication method should they use to provide highly secure, passwordless sign-in for shared workstations?
- A.SMS-based authentication
- B.Microsoft Authenticator app
- C.FIDO2 security keys
- D.Voice call authentication
Show answer & explanation
Correct answer: C — FIDO2 security keys
- A. Incorrect. SMS-based authentication requires a mobile phone to receive a text message, which is prohibited on the factory floor. Furthermore, SMS is not a passwordless method and is vulnerable to interception and SIM swapping.
- B. Incorrect. The Microsoft Authenticator app requires a smartphone to approve push notifications or generate TOTP codes. Since mobile phones are not allowed, this method is not viable for this scenario.
- C. Correct. FIDO2 security keys provide a hardware-based, phishing-resistant, passwordless authentication method. They do not require a mobile device, making them the ideal solution for high-security environments and shared workstations where phones are prohibited.
- D. Incorrect. Voice call authentication requires access to a phone to receive a call. It is neither passwordless nor permitted in an environment where mobile devices are banned.