nerdexam
Microsoft

MS-102 · Question #304

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a…

The correct answer is A. Join all the devices to contoso.com. To implement passwordless sign-in for workgroup Windows 10 devices to Microsoft Entra ID, the devices must first be joined to Microsoft Entra ID.

Submitted by ravi_2018· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?

Options

  • AJoin all the devices to contoso.com.
  • BDeploy Microsoft Entra Application Proxy.
  • CDeploy the Microsoft Entra Connect provisioning agent.
  • DDeploy the Microsoft Authenticator app.

How the community answered

(16 responses)
  • A
    75% (12)
  • B
    6% (1)
  • C
    6% (1)
  • D
    13% (2)

Why each option

To implement passwordless sign-in for workgroup Windows 10 devices to Microsoft Entra ID, the devices must first be joined to Microsoft Entra ID.

AJoin all the devices to contoso.com.Correct

Devices must be Microsoft Entra joined or Hybrid Microsoft Entra joined to use passwordless authentication methods like Windows Hello for Business or FIDO2 security keys for sign-in, as these methods rely on device registration and trust with Microsoft Entra ID. Since the devices are currently in a workgroup, joining them to contoso.com (Microsoft Entra ID) establishes the necessary trust and enables the use of these authentication options for passwordless sign-in to Entra ID resources.

BDeploy Microsoft Entra Application Proxy.

Microsoft Entra Application Proxy provides secure remote access to on-premises web applications and is not directly related to enabling passwordless sign-in for Windows 10 devices to Microsoft Entra ID itself.

CDeploy the Microsoft Entra Connect provisioning agent.

The Microsoft Entra Connect provisioning agent is used for HR-driven provisioning or cloud sync to synchronize identities from on-premises directories to Microsoft Entra ID, which is not required for enabling passwordless sign-in for existing Microsoft Entra users.

DDeploy the Microsoft Authenticator app.

Deploying the Microsoft Authenticator app is a component of some passwordless methods (e.g., phone sign-in), but it does not address the fundamental requirement of enabling workgroup devices for passwordless sign-in to Microsoft Entra ID, which first requires device registration.

Concept tested: Microsoft Entra device registration for passwordless

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-passwordless

Topics

#Passwordless Sign-in#Microsoft Entra Device Management#Microsoft Entra Join#Identity and Access Management

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice