exam questions

Exam MS-900 All Questions

View all questions & answers for the MS-900 exam

Exam MS-900 topic 1 question 223 discussion

Actual exam question from Microsoft's MS-900
Question #: 223
Topic #: 1
[All MS-900 Questions]

A company deploys Microsoft Azure AD. You enable multi-factor authentication.
You need to inform users about the multi-factor authentication methods that they can use.
Which of the following methods is NOT a valid multi-factor authentication method in Microsoft 365?

  • A. Receive an automated call on the desk phone that includes a verification code.
  • B. Use the Microsoft Authenticator mobile application to receive a notification and authenticate.
  • C. Receive a call on a phone.
  • D. Enter a Windows 10 PIN code when prompted.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AntonioTech
3 months, 2 weeks ago
Selected Answer: D
D is correct: Valid Microsoft 365 Multi-Factor Authentication (MFA) methods include: A. Receive an automated call on the desk phone that includes a verification code ✔️ Valid – Users can verify their identity via an automated phone call. B. Use the Microsoft Authenticator mobile application to receive a notification and authenticate ✔️ Valid – This is a preferred and secure method using push notifications. C. Receive a call on a phone ✔️ Valid – Similar to option A, users can answer a call and press a key to verify. ❌ D. Enter a Windows 10 PIN code when prompted ✖️ Not a valid Microsoft 365 MFA method – A Windows Hello PIN is a local device authentication method. It’s considered a single factor (something you know), and while secure on the device, it doesn't count toward Microsoft 365 MFA, which must include two distinct factors like: Something you know (password) Something you have (authenticator app, phone) Something you are (biometrics)
upvoted 2 times
...
Sergio_G_S
7 months, 1 week ago
Selected Answer: A
Receive an automated call on the desk phone that includes a verification cod
upvoted 1 times
...
NoursBear
10 months, 3 weeks ago
I go with A - they want to trick you with D - there are situations when you have to enter a 2 letter code from the authenticator that’s true for mobiles not suite with W10
upvoted 1 times
NoursBear
10 months, 3 weeks ago
D may be true for the first time setup
upvoted 1 times
...
NoursBear
10 months ago
not to mention MFA with desk phone could be tricky on the move lol
upvoted 1 times
...
...
HOzwei
11 months, 2 weeks ago
Selected Answer: A
A, no code is provided via call.
upvoted 1 times
...
momowagdy
1 year, 4 months ago
Phone call verification With phone call verification during SSPR or Azure AD Multi-Factor Authentication, an automated voice call is made to the phone number registered by the user. To complete the sign-in process, the user is prompted to press # on their keypad. The calling number that a user receives the voice call from differs for each country. See phone call settings to view all possible voice call numbers. Office phone verification With office phone call verification during SSPR or Azure AD Multi-Factor Authentication, an automated voice call is made to the phone number registered by the user. To complete the sign-in process, the user is prompted to press # on their keypad.
upvoted 1 times
...
TypeRR
1 year, 7 months ago
I got this question in the exam on 2023-06-28.
upvoted 2 times
...
jim85
2 years ago
I'd say D as the problem is with D is that it says "Windows 10 PIN" which can be out of Hello for Business scope, meanwhile A is definitely a valid answer.
upvoted 3 times
...
BTL_Happy
2 years, 3 months ago
A, no code will be given via the phone call
upvoted 2 times
...
bn1234
3 years ago
I'm going with answer D A PIN code is NOT a form of MFA for Microsoft 365 (see link below). A PIN code is part of part of Windows Hello for Business, but the question does not reference Windows Hello for Business - only that MFA has been enabled and the answer option of using a PIN as part of MFA. Think about it, if you log into Exchange Online by entering your username and password, it would never prompt for a PIN as both your password and PIN are both 'things you know', therefore NOT MFA. https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks#available-verification-methods
upvoted 1 times
wando5000
2 years, 4 months ago
I think answer A is incorrect In the table of the link below; Windows hello for Business is listed as a primary authentication method and can be used in MFA as a secondary authentication method "by being used in FIDO2 authentication. This requires users to be enabled for FIDO2 authentication to work successfully." So it IS a valid multi-factor authentication method in Microsoft 365 "Some authentication methods can be used as the primary factor when you sign into an application or device, such as using a FIDO2 security key or a password. Other authentication methods are only available as a secondary factor when you use Azure AD Multi-Factor Authentication or SSPR." Note that 'voice call' is also listed as MFA as a secondary authentication method (doesn't say 'receive a call on a phone' or 'receive an automated call...') https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods
upvoted 1 times
...
...
Aniel
3 years, 5 months ago
To confuse even more: A is an answer because you can't get code on the desk phone (phone call requires user to press #) And it is not D, because: If a user has signed into their Azure AD registered device with Windows Hello, their Windows Hello for Business key will be used to authenticate the user's work identity when they try to use Azure AD resources. The Windows Hello for Business key meets Azure AD multi-factor authentication (MFA) requirements and reduces the number of MFA prompts users will see when accessing resources.
upvoted 3 times
...
syu31svc
3 years, 7 months ago
This is same as Qn 107 I'll take D
upvoted 2 times
...
Phongsanth
3 years, 9 months ago
I go with answer A. Win10 PIN is part of Windows Hello for business. It can use with MFA. https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview --- https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods ---- https://techcommunity.microsoft.com/t5/azure-active-directory-identity/it-s-time-to-hang-up-on-phone-transports-for-authentication/ba-p/1751752
upvoted 4 times
...
maaten
3 years, 9 months ago
Isn't answer D a part of Windows Hello?
upvoted 2 times
Solomonmoon00
3 years, 9 months ago
Which is also NOT part of MFA as MFA is the second authentication on logging into Microsoft 365 online. It might sound confusing as the regular online login and Windows screen login get their IAM security authentication from Azure AD and/or AD DS but basically, MFA is not part of Windows login security.
upvoted 8 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...