nerdexam
Microsoft

SC-300 · Question #355

You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings: - Require users to register when signing in: Yes - Number of methods required to…

The correct answer is B. a mobile app notification. Mobile app notification (Microsoft Authenticator) is a valid SSPR authentication method in Microsoft Entra ID. Microsoft supports several built-in methods including mobile app notification, mobile app code, email (external), mobile phone, and security questions - all…

Submitted by klara.se· Mar 6, 2026Implement authentication and access management solution

Question

You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings:

  • Require users to register when signing in: Yes
  • Number of methods required to reset: 1

What is a valid authentication method available to users?

Options

  • Aan email to an address outside your organization
  • Ba mobile app notification
  • Ca smartcard
  • Dan email to an address in your organization

How the community answered

(39 responses)
  • B
    90% (35)
  • C
    3% (1)
  • D
    8% (3)

Explanation

Mobile app notification (Microsoft Authenticator) is a valid SSPR authentication method in Microsoft Entra ID. Microsoft supports several built-in methods including mobile app notification, mobile app code, email (external), mobile phone, and security questions - all configurable within the SSPR policy.

Why the distractors are wrong:

  • Option A (external email) is actually a valid SSPR method, but it must be an email address outside the organization - wait, this seems like a trick: external email IS valid for SSPR, but Option D (internal/organizational email) is NOT valid, as Microsoft specifically excludes organizational email addresses to prevent a single point of failure if the account is compromised.
  • Option C (smartcard) is not a supported SSPR authentication method; smartcards are used for primary sign-in authentication, not self-service password reset.
  • Option D (organizational email) is explicitly excluded from SSPR because if a user is locked out, they likely cannot access their work email anyway, defeating the purpose.

Memory Tip: Think "SSPR needs an escape hatch" - all valid SSPR methods must be accessible independently of the corporate account (external email, mobile app, phone). Anything tied to your organization's ecosystem (work email, smartcard) is excluded because it fails when you need it most.

Topics

#SSPR#Authentication Methods#Microsoft Entra ID#User Identities

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice