nerdexam
Microsoft

AZ-500 · Question #438

Drag and Drop Question You have an Azure AD tenant that contains the users shown in the following table. You enable passwordless authentication for the tenant. Which authentication method can each…

The correct answer is Microsoft Authenticator app only; Microsoft Authenticator app, Windows Hello for Business, and FIDO2 security key. The question involves two users with different configurations. The first user (likely using a non-Windows device or lacking TPM/biometric hardware) can only use the Microsoft Authenticator app for passwordless authentication, as Windows Hello for Business requires a Windows…

Submitted by dimitri_ru· Mar 6, 2026Implement and Manage Identity and Access in Azure AD - specifically managing authentication methods including passwordless authentication options (Microsoft Authenticator, Windows Hello for Business, FIDO2 security keys)

Question

Drag and Drop Question You have an Azure AD tenant that contains the users shown in the following table. You enable passwordless authentication for the tenant. Which authentication method can each user use for passwordless authentication? To answer, drag the appropriate authentication methods to the correct users. Each authentication method may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #438 exhibit 1
AZ-500 question #438 exhibit 2

Answer Area

Drag items

FIDO2 security key onlyMicrosoft Authenticator app onlyWindows Hello for Business onlyMicrosoft Authenticator app and Windows Hello for Business onlyWindows Hello for Business and FIDO2 security key onlyMicrosoft Authenticator app, Windows Hello for Business, and FIDO2 security key

Correct arrangement

  • Microsoft Authenticator app only
  • Microsoft Authenticator app, Windows Hello for Business, and FIDO2 security key

Explanation

The question involves two users with different configurations. The first user (likely using a non-Windows device or lacking TPM/biometric hardware) can only use the Microsoft Authenticator app for passwordless authentication, as Windows Hello for Business requires a Windows 10/11 device with TPM and biometric/PIN support, and FIDO2 requires compatible hardware. The second user (with a fully compliant Windows device and compatible hardware) has access to all three passwordless methods: Microsoft Authenticator app, Windows Hello for Business, and FIDO2 security key, since all prerequisites are met.

Topics

#Passwordless Authentication#Azure AD Authentication Methods#Windows Hello for Business#FIDO2 Security Keys

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice