MS-102 · Question #304
Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a…
The correct answer is A. Join all the devices to contoso.com. To implement passwordless sign-in for workgroup Windows 10 devices to Microsoft Entra ID, the devices must first be joined to Microsoft Entra ID.
Question
Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?
Options
- AJoin all the devices to contoso.com.
- BDeploy Microsoft Entra Application Proxy.
- CDeploy the Microsoft Entra Connect provisioning agent.
- DDeploy the Microsoft Authenticator app.
How the community answered
(16 responses)- A75% (12)
- B6% (1)
- C6% (1)
- D13% (2)
Why each option
To implement passwordless sign-in for workgroup Windows 10 devices to Microsoft Entra ID, the devices must first be joined to Microsoft Entra ID.
Devices must be Microsoft Entra joined or Hybrid Microsoft Entra joined to use passwordless authentication methods like Windows Hello for Business or FIDO2 security keys for sign-in, as these methods rely on device registration and trust with Microsoft Entra ID. Since the devices are currently in a workgroup, joining them to contoso.com (Microsoft Entra ID) establishes the necessary trust and enables the use of these authentication options for passwordless sign-in to Entra ID resources.
Microsoft Entra Application Proxy provides secure remote access to on-premises web applications and is not directly related to enabling passwordless sign-in for Windows 10 devices to Microsoft Entra ID itself.
The Microsoft Entra Connect provisioning agent is used for HR-driven provisioning or cloud sync to synchronize identities from on-premises directories to Microsoft Entra ID, which is not required for enabling passwordless sign-in for existing Microsoft Entra users.
Deploying the Microsoft Authenticator app is a component of some passwordless methods (e.g., phone sign-in), but it does not address the fundamental requirement of enabling workgroup devices for passwordless sign-in to Microsoft Entra ID, which first requires device registration.
Concept tested: Microsoft Entra device registration for passwordless
Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-passwordless
Topics
Community Discussion
No community discussion yet for this question.