Instiq
Chapter 3 · Authentication and Conditional Access·v1.0.0·Updated 6/28/2026·~15 min

What's changed: Created SC-300 Chapter 3 (Domain 2: authentication methods (CBA/TAP/passkeys FIDO2/Authenticator/MFA/SSPR/Windows Hello/password protection/Entra Kerberos); Conditional Access (assignments/controls/session/CAE/authentication context/protected actions/templates/report-only/break-glass exclusion); ID Protection (user/sign-in risk/risky workload id/registration campaigns); Global Secure Access (GSA client/Entra Private Access ZTNA/Entra Internet Access SWG/Internet Access for M365/tenant restrictions)).

3.1Authentication methods and multifactor authentication

Key points

Understand authentication methods (certificate-based auth, Temporary Access Pass, Microsoft Authenticator, passkeys/FIDO2), tenant-wide MFA settings, self-service password reset (SSPR), Windows Hello for Business, Entra password protection, and Entra Kerberos for hybrid.

Authentication is the front line of identity protection. The access administrator designs a methods policy that leans toward phishing-resistant options while preserving user experience (passwordless, self-service).

3.1.1Authentication methods and phishing resistance

The authentication methods policy controls which methods are available and to whom. The strongest are phishing-resistant passkeys (FIDO2) and certificate-based authentication (CBA). Microsoft Authenticator (number matching, push) is widely used, and Temporary Access Pass (TAP) provides a time-limited temporary credential for passwordless onboarding or when a method is lost. Architects prioritize passkeys/CBA for "phishing-resistant MFA" and reduce weak methods like SMS.

3.1.2SSPR, Windows Hello, and password protection

Self-service password reset (SSPR) lets users reset their own password using registered methods, reducing help-desk load (write back on-prem via password writeback). Windows Hello for Business provides on-device passwordless authentication via biometric/PIN. Entra password protection rejects weak/guessable passwords via global/custom banned-password lists and extends to on-prem AD. Together they advance "passwordless + self-service + eliminating weak passwords."

Exam point

Cues: "phishing-resistant MFA" = passkeys (FIDO2)/certificate-based auth (CBA). "passwordless onboarding / temporary credential when a method is lost" = Temporary Access Pass (TAP). "users reset their own password" = SSPR (+ writeback to on-prem). "ban weak passwords" = Entra password protection (banned lists).

Warning

Watch the mix-ups: (1) TAP is a temporary, time-limited credential—not a permanent method. (2) SMS/voice are MFA but low phishing-resistance—move to stronger methods. (3) Reflecting SSPR to on-prem requires password writeback.

Diagram of phishing-resistant (passkeys/FIDO2, certificate-based auth), Temporary Access Pass/Microsoft Authenticator (number matching), SSPR (+writeback)/Windows Hello/Entra password protection.
Prioritize phishing resistance

3.1.3Section summary

  • Manage via the methods policy; prioritize phishing-resistant passkeys (FIDO2)/CBA, reduce SMS, etc.
  • TAP = time-limited temp credential (onboarding/loss); SSPR = self-reset (+writeback); Windows Hello = on-device passwordless
  • Entra password protection = banned-password lists reject weak passwords (extensible to on-prem AD)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Your org wants to require phishing-resistant MFA org-wide. Which authentication methods fit best?

Q2. You want new hires to onboard passwordless and to issue a time-limited temporary credential to users who lost a method. Which is best?

Q3. To reduce help-desk load, you want users to reset their own password via registered methods and reflect it to on-prem AD. Which is best?

Q4. You want to reject weak/guessable passwords like "Password123" in both cloud and on-prem AD. Which is best?

Q5. You want passwordless sign-in via biometric/PIN on Windows devices. Which is best?

Check your understandingPractice questions for Chapter 3: Authentication and Conditional Access