An Azure AD tenant contains a group named Group1. You must ensure that members of Group1 sign in using passwordless authentication. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the Microsoft Authenticator authentication method policy..
Why this is the answer
To enforce passwordless authentication for Group1 members, you should configure the Microsoft Authenticator authentication method policy. This policy specifically manages which authentication methods are available to users and groups, including passwordless phone sign-in with the Microsoft Authenticator app. The sign-in risk policy is used for detecting and responding to risky sign-ins, not for enforcing specific authentication methods. Creating a Conditional Access policy alone is insufficient because while Conditional Access can require specific authentication strengths, the underlying authentication method (like passwordless sign-in) must first be enabled and configured via an authentication method policy. The certificate-based authentication (CBA) policy is for using X.509 certificates for authentication, which is a different passwordless method than what's typically implied by "passwordless authentication" in the context of Microsoft Authenticator.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed