nerdexam
Microsoft

SC-300 · Question #360

You have a Microsoft 365 tenant. All users have mobile phones and Windows 10 laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity…

The correct answer is A. Windows Hello for Business. Windows Hello for Business (A) is correct because it uses biometric authentication (fingerprint, facial recognition) or a PIN stored locally on the device itself - requiring no mobile phone signal, Wi-Fi, or internet connectivity beyond what the wired network provides for…

Submitted by akirajp· Mar 6, 2026Implement authentication and access management solution

Question

You have a Microsoft 365 tenant. All users have mobile phones and Windows 10 laptops. The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from the remote locations, the users connect their laptop to a wired network that has internet access. You plan to implement multi-factor authentication (MFA). Which MFA authentication method can the users use from the remote location?

Options

  • AWindows Hello for Business
  • Ban app password
  • Ca notification through the Microsoft Authenticator app
  • Dsecurity questions

How the community answered

(32 responses)
  • A
    78% (25)
  • B
    6% (2)
  • C
    3% (1)
  • D
    13% (4)

Explanation

Windows Hello for Business (A) is correct because it uses biometric authentication (fingerprint, facial recognition) or a PIN stored locally on the device itself - requiring no mobile phone signal, Wi-Fi, or internet connectivity beyond what the wired network provides for Microsoft 365 access. It authenticates the user directly from the laptop hardware, making it ideal for environments with limited connectivity.

Why the distractors are wrong:

  • (B) App passwords are used to allow legacy apps to bypass MFA, not as a standalone MFA method, and still require an initial setup requiring connectivity.
  • (C) Microsoft Authenticator notifications require the mobile phone to have an active internet or cellular connection to receive push notifications - which the remote location explicitly lacks.
  • (D) Security questions are used for self-service password reset (SSPR), not as a supported MFA authentication method in Microsoft 365.

Memory tip: Think of Windows Hello for Business as the "self-contained" MFA method - everything it needs lives on the device, so it works regardless of phone signal or Wi-Fi. If the question mentions no phone connectivity, Windows Hello for Business is almost always the answer.

Topics

#Multi-factor authentication#Windows Hello for Business#Authentication methods#Azure AD MFA

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice