nerdexam
Microsoft

SC-300 · Question #127

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that has multi-factor authentication (MFA) enabled. The account lockout settings are configured as shown in the following…

The correct answer is A user account will be locked out if the user enters the wrong [...] three times.: authentication method; If a user account is locked, the user can sign in again successfully after [...] minutes.: 60. This question assesses understanding of Azure Active Directory (Azure AD) Multi-Factor Authentication (MFA) account lockout settings based on the provided exhibit. Statement 1: A user account will be locked out if the user enters the wrong [...] three times. (Answer…

Submitted by fernanda_arg· Mar 6, 2026Implement and manage user identities

Question

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that has multi-factor authentication (MFA) enabled. The account lockout settings are configured as shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point. Answer:

Exhibit

SC-300 question #127 exhibit

Answer Area

  • A user account will be locked out if the user enters the wrong [...] three times.authentication method
    authentication methodPINauthenticator app code
  • If a user account is locked, the user can sign in again successfully after [...] minutes.60
    3060

Explanation

This question assesses understanding of Azure Active Directory (Azure AD) Multi-Factor Authentication (MFA) account lockout settings based on the provided exhibit.

Statement 1: A user account will be locked out if the user enters the wrong [...] three times. (Answer: authentication method)

The exhibit's 'Account lockout' settings clearly state: 'Number of MFA denials to trigger account lockout: 3'. The note associated with these settings specifies that this feature applies to 'denied authentication attempts'. An MFA denial occurs when a user fails to correctly provide their chosen multi-factor authentication 'authentication method' (e.g., wrong PIN, incorrect app approval). Therefore, entering the wrong authentication method three times will lead to an account lockout.

Statement 2: If a user account is locked, the user can sign in again successfully after [...] minutes. (Answer: 60)

When a user account is locked due to too many MFA denials, the ability to 'sign in again successfully' depends on the lockout counter being reset. The exhibit shows 'Minutes until account lockout counter is reset: 60'. This setting dictates that after the last failed attempt, the system waits 60 minutes before clearing the count of failed MFA denials. Once the counter is reset, the user can then make new attempts to sign in. While there is also a 'Minutes until account is automatically unblocked: 30' setting, the 'Minutes until account lockout counter is reset' is the critical duration that allows for a successful sign-in by clearing the history of failed attempts.

Topics

#Azure AD#Account Lockout Policy#MFA Security#Authentication Configuration

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice