220-1002 · Question #14
Ann, a user, is attempting to log in to her email service form a third-party email client on her phone. When Ann enters her usual username and password, she receives an error message saying the…
The correct answer is C. Multifactor authentication. Multifactor authentication (MFA) on an email account can block third-party clients that do not natively support MFA flows, causing credential errors even after a password reset. The third-party app cannot complete the additional authentication challenge.
Question
Ann, a user, is attempting to log in to her email service form a third-party email client on her phone. When Ann enters her usual username and password, she receives an error message saying the credentials are invalid. Ann then decides to reset her email password, but after the reset, the new credentials still do not work in the third-party email client. Which of the following settings or features is responsible for the problems Ann is experiencing?
Options
- AFull device encryption
- BAccount lock
- CMultifactor authentication
- DStrong password requirements
How the community answered
(25 responses)- A16% (4)
- B4% (1)
- C76% (19)
- D4% (1)
Why each option
Multifactor authentication (MFA) on an email account can block third-party clients that do not natively support MFA flows, causing credential errors even after a password reset. The third-party app cannot complete the additional authentication challenge.
Full device encryption protects data at rest and does not affect the validity of account credentials used to authenticate to a remote email service.
An account lock would prevent access, but resetting the password would unlock the account and restore access, which did not happen here.
When MFA is enabled on an account, many third-party email clients cannot handle the secondary authentication challenge and report credentials as invalid. A password reset does not resolve the issue because the problem is not the password itself but the client's inability to complete the MFA prompt - typically resolved by generating an app-specific password from the provider.
Strong password requirements would be satisfied after a password reset if the new password meets the complexity criteria, so this would not persist after the reset.
Concept tested: MFA impact on third-party email client authentication
Source: https://support.microsoft.com/en-us/account-billing/using-app-passwords-with-apps-that-don-t-support-two-step-verification-5896ed9b-4263-e681-128a-a6f2979a7944
Topics
Community Discussion
No community discussion yet for this question.