nerdexam
Microsoft

MS-900 · Question #109

A company deploys Microsoft Azure AD. You enable multi-factor authentication. You need to inform users about the multi-factor authentication methods that they can use. Which of the following methods…

The correct answer is D. Enter a Windows 10 PIN code when prompted. The question identifies valid and invalid Multi-Factor Authentication (MFA) methods for Microsoft 365 through Azure AD. Entering a Windows 10 PIN code is not a direct MFA method for cloud services, unlike phone calls or authenticator app notifications.

Submitted by eva_at· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company deploys Microsoft Azure AD. You enable multi-factor authentication. You need to inform users about the multi-factor authentication methods that they can use. Which of the following methods is NOT a valid multi-factor authentication method in Microsoft 365?

Options

  • AReceive an automated call on the desk phone that includes a verification code.
  • BUse the Microsoft Authenticator mobile application to receive a notification and authenticate.
  • CReceive a call on a phone.
  • DEnter a Windows 10 PIN code when prompted.

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    88% (35)

Why each option

The question identifies valid and invalid Multi-Factor Authentication (MFA) methods for Microsoft 365 through Azure AD. Entering a Windows 10 PIN code is not a direct MFA method for cloud services, unlike phone calls or authenticator app notifications.

AReceive an automated call on the desk phone that includes a verification code.

Receiving an automated call on a desk phone that includes a verification code is a valid Azure AD Multi-Factor Authentication method using voice call verification.

BUse the Microsoft Authenticator mobile application to receive a notification and authenticate.

Using the Microsoft Authenticator mobile application for notifications or time-based one-time passcodes is a primary and highly recommended Azure AD Multi-Factor Authentication method.

CReceive a call on a phone.

Receiving a call on a phone (mobile or landline) and responding to verify identity is a valid Azure AD Multi-Factor Authentication method via voice call verification.

DEnter a Windows 10 PIN code when prompted.Correct

A Windows 10 PIN is used for local device access, such as signing into Windows with Windows Hello. While Windows Hello for Business integrates with Azure AD, the PIN itself is a credential to unlock the device's authentication mechanisms (like TPM-protected keys) and is not a direct second factor verified by the Azure AD cloud service during a Microsoft 365 login.

Concept tested: Azure AD Multi-Factor Authentication methods

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods

Topics

#multi-factor authentication#MFA methods#Azure AD MFA#Windows 10 PIN

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice