nerdexam
Microsoft

MS-900 · Question #57

A company deploys Microsoft Azure AD. You enable multi-factor authentication. You need to inform users about the multi-factor authentication methods that they can use. Which of the following methods i

The correct answer is A. Receive an automated call on the desk phone that includes a verification code. This question tests knowledge of valid Multi-Factor Authentication (MFA) methods supported in Microsoft 365/Azure AD. One of the listed options describes a method that does not match how MFA phone call verification actually works.

Submitted by rania.sa· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company deploys Microsoft Azure AD. You enable multi-factor authentication. You need to inform users about the multi-factor authentication methods that they can use. Which of the following methods is NOT a valid multi-factor authentication method in Microsoft 365?

Options

  • AReceive an automated call on the desk phone that includes a verification code
  • BInsert a small card in to a desktop computer and provide a PIN code when prompted
  • CReceive a call on a mobile phone and select the pound sign (#) when prompted
  • DReceive an SMS text message that includes a verification code

How the community answered

(41 responses)
  • A
    93% (38)
  • B
    2% (1)
  • C
    5% (2)

Why each option

This question tests knowledge of valid Multi-Factor Authentication (MFA) methods supported in Microsoft 365/Azure AD. One of the listed options describes a method that does not match how MFA phone call verification actually works.

AReceive an automated call on the desk phone that includes a verification codeCorrect

Automated calls to desk phones in Azure AD MFA do not provide a verbal verification code; instead, the user is prompted to press the pound sign (#) to approve the authentication. The method described - receiving an automated call that reads out a verification code - is not how Microsoft 365 MFA phone call verification functions. This makes option A the invalid method, as it misrepresents the actual call-based MFA flow.

BInsert a small card in to a desktop computer and provide a PIN code when prompted

Inserting a smart card and providing a PIN is a valid hardware-based authentication method (smart card authentication) supported in Azure AD when configured with certificate-based authentication, making it a legitimate MFA method.

CReceive a call on a mobile phone and select the pound sign (#) when prompted

Receiving a call on a mobile phone and pressing the pound sign (#) is a valid and accurately described Azure AD MFA method, as this is exactly how phone call verification works in Microsoft 365 MFA.

DReceive an SMS text message that includes a verification code

Receiving an SMS text message containing a verification code is a valid Azure AD MFA method, as SMS-based one-time passcodes are a supported authentication option in Microsoft 365.

Concept tested: Valid MFA authentication methods in Azure AD

Source: https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

Topics

#MFA methods#Azure AD MFA#authentication

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice