What's changed: Created SC-300 Chapter 3 (Domain 2: authentication methods (CBA/TAP/passkeys FIDO2/Authenticator/MFA/SSPR/Windows Hello/password protection/Entra Kerberos); Conditional Access (assignments/controls/session/CAE/authentication context/protected actions/templates/report-only/break-glass exclusion); ID Protection (user/sign-in risk/risky workload id/registration campaigns); Global Secure Access (GSA client/Entra Private Access ZTNA/Entra Internet Access SWG/Internet Access for M365/tenant restrictions)).
3.1Authentication methods and multifactor authentication
Understand authentication methods (certificate-based auth, Temporary Access Pass, Microsoft Authenticator, passkeys/FIDO2), tenant-wide MFA settings, self-service password reset (SSPR), Windows Hello for Business, Entra password protection, and Entra Kerberos for hybrid.
Authentication is the front line of identity protection. The access administrator designs a methods policy that leans toward phishing-resistant options while preserving user experience (passwordless, self-service).
3.1.1Authentication methods and phishing resistance
The authentication methods policy controls which methods are available and to whom. The strongest are phishing-resistant passkeys (FIDO2) and certificate-based authentication (CBA). Microsoft Authenticator (number matching, push) is widely used, and Temporary Access Pass (TAP) provides a time-limited temporary credential for passwordless onboarding or when a method is lost. Architects prioritize passkeys/CBA for "phishing-resistant MFA" and reduce weak methods like SMS.
3.1.2SSPR, Windows Hello, and password protection
Self-service password reset (SSPR) lets users reset their own password using registered methods, reducing help-desk load (write back on-prem via password writeback). Windows Hello for Business provides on-device passwordless authentication via biometric/PIN. Entra password protection rejects weak/guessable passwords via global/custom banned-password lists and extends to on-prem AD. Together they advance "passwordless + self-service + eliminating weak passwords."
Cues: "phishing-resistant MFA" = passkeys (FIDO2)/certificate-based auth (CBA). "passwordless onboarding / temporary credential when a method is lost" = Temporary Access Pass (TAP). "users reset their own password" = SSPR (+ writeback to on-prem). "ban weak passwords" = Entra password protection (banned lists).
Watch the mix-ups: (1) TAP is a temporary, time-limited credential—not a permanent method. (2) SMS/voice are MFA but low phishing-resistance—move to stronger methods. (3) Reflecting SSPR to on-prem requires password writeback.
3.1.3Section summary
- Manage via the methods policy; prioritize phishing-resistant passkeys (FIDO2)/CBA, reduce SMS, etc.
- TAP = time-limited temp credential (onboarding/loss); SSPR = self-reset (+writeback); Windows Hello = on-device passwordless
- Entra password protection = banned-password lists reject weak passwords (extensible to on-prem AD)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Your org wants to require phishing-resistant MFA org-wide. Which authentication methods fit best?
Q2. You want new hires to onboard passwordless and to issue a time-limited temporary credential to users who lost a method. Which is best?
Q3. To reduce help-desk load, you want users to reset their own password via registered methods and reflect it to on-prem AD. Which is best?
Q4. You want to reject weak/guessable passwords like "Password123" in both cloud and on-prem AD. Which is best?
Q5. You want passwordless sign-in via biometric/PIN on Windows devices. Which is best?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

