What's changed: Created SC-300 Chapter 3 (Domain 2: authentication methods (CBA/TAP/passkeys FIDO2/Authenticator/MFA/SSPR/Windows Hello/password protection/Entra Kerberos); Conditional Access (assignments/controls/session/CAE/authentication context/protected actions/templates/report-only/break-glass exclusion); ID Protection (user/sign-in risk/risky workload id/registration campaigns); Global Secure Access (GSA client/Entra Private Access ZTNA/Entra Internet Access SWG/Internet Access for M365/tenant restrictions)).
3.1Authentication methods and multifactor authentication
Understand authentication methods (certificate-based auth, Temporary Access Pass, Microsoft Authenticator, passkeys/FIDO2), tenant-wide MFA settings, self-service password reset (SSPR), Windows Hello for Business, Entra password protection, and Entra Kerberos for hybrid.
Authentication is the front line of identity protection. The access administrator designs a methods policy that leans toward phishing-resistant options while preserving user experience (passwordless, self-service).
3.1.1Authentication methods and phishing resistance
The authentication methods policy controls which methods are available and to whom. The strongest are phishing-resistant passkeys (FIDO2) and certificate-based authentication (CBA). Microsoft Authenticator (number matching, push) is widely used, and Temporary Access Pass (TAP) provides a time-limited temporary credential for passwordless onboarding or when a method is lost. Architects prioritize passkeys/CBA for "phishing-resistant MFA" and reduce weak methods like SMS.
3.1.2SSPR, Windows Hello, and password protection
Self-service password reset (SSPR) lets users reset their own password using registered methods, reducing help-desk load (write back on-prem via password writeback). Windows Hello for Business provides on-device passwordless authentication via biometric/PIN. Entra password protection rejects weak/guessable passwords via global/custom banned-password lists and extends to on-prem AD. Together they advance "passwordless + self-service + eliminating weak passwords."
Cues: "phishing-resistant MFA" = passkeys (FIDO2)/certificate-based auth (CBA). "passwordless onboarding / temporary credential when a method is lost" = Temporary Access Pass (TAP). "users reset their own password" = SSPR (+ writeback to on-prem). "ban weak passwords" = Entra password protection (banned lists).
Watch the mix-ups: (1) TAP is a temporary, time-limited credential—not a permanent method. (2) SMS/voice are MFA but low phishing-resistance—move to stronger methods. (3) Reflecting SSPR to on-prem requires password writeback.
3.1.3Section summary
- Manage via the methods policy; prioritize phishing-resistant passkeys (FIDO2)/CBA, reduce SMS, etc.
- TAP = time-limited temp credential (onboarding/loss); SSPR = self-reset (+writeback); Windows Hello = on-device passwordless
- Entra password protection = banned-password lists reject weak passwords (extensible to on-prem AD)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Your org wants to require phishing-resistant MFA org-wide. Which authentication methods fit best?
Q2. You want new hires to onboard passwordless and to issue a time-limited temporary credential to users who lost a method. Which is best?
Q3. To reduce help-desk load, you want users to reset their own password via registered methods and reflect it to on-prem AD. Which is best?
Q4. You want to reject weak/guessable passwords like "Password123" in both cloud and on-prem AD. Which is best?
Q5. You want passwordless sign-in via biometric/PIN on Windows devices. Which is best?

