nerdexam
Microsoft

SC-300 · Question #153

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. User2 reports that he can only configure multi-factor authentication (MFA)…

The correct answer is Configuration: Modify security defaults.; User: User1 only. When Azure AD Security Defaults are enabled, MFA is enforced but users are restricted to using only the Microsoft Authenticator app, which explains why User2 cannot configure alternate MFA methods like SMS or phone calls. Disabling Security Defaults (modifying them) allows…

Submitted by kavita_s· Mar 6, 2026Manage Azure Active Directory (Azure AD) identities and secure access - specifically configuring authentication methods and understanding the impact of Security Defaults on MFA registration options (AZ-104 / SC-300 Identity and Access Management)

Question

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. User2 reports that he can only configure multi-factor authentication (MFA) to use the Microsoft Authenticator app. You need to ensure that User2 can configure alternate MFA methods. Which configuration is required, and which user should perform the configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

SC-300 question #153 exhibit

Answer Area

  • ConfigurationModify security defaults.
    Enable access reviews.Enable Azure AD Privileged Identity Management (PIM).Modify security defaults.
  • UserUser1 only
    User1 onlyUser2 onlyUser3 onlyUser1 and User2 onlyUser1 and User3 onlyUser2 and User3 only

Explanation

When Azure AD Security Defaults are enabled, MFA is enforced but users are restricted to using only the Microsoft Authenticator app, which explains why User2 cannot configure alternate MFA methods like SMS or phone calls. Disabling Security Defaults (modifying them) allows administrators to implement Conditional Access policies or allow users to register multiple MFA methods. User1, as a Global Administrator (the only role with sufficient privileges to modify Security Defaults in Azure AD), is the correct user to perform this configuration change.

Topics

#Azure AD Security Defaults#Multi-Factor Authentication (MFA)#Azure AD Roles and Permissions#Identity Management

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice