Which passwordless method works on Windows, Android, and iOS?

Answer Correct answer: B — Use FIDO2-compliant security keys, the only listed passwordless method supported on Windows, Android, and iOS.

You have a Microsoft 365 subscription. You need to implement a passwordless authentication solution that supports the following device types: • Windows • Android • iOS The solution must use the same authentication method for all devices. Which authentication method should you use?

  1. the Microsoft Authentication app
  2. FIDO2-compliant security keys Correct Answer
  3. multi-factor authentication (MFA)
  4. Windows Hello for Business

Community Votes

A
50%
B
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests platform support for each passwordless credential in Microsoft Entra ID; the trap is assuming Microsoft Authenticator works everywhere, when its passwordless phone sign-in credential exists only on iOS and Android.

This MS-102 question asks which single passwordless authentication method covers Windows, Android, and iOS devices at the same time. FIDO2-compliant security keys are confirmed as the answer because they are the only listed credential supported across all three platforms.

Picking the Microsoft Authenticator app (A) because it is Microsoft's flagship passwordless option — but its phone sign-in credential is issued only on iOS and Android, so Windows devices are left without a matching passwordless method.

Community Discussion (13 comments)

solderboy 👍 13 Selected: A
https://www.examtopics.com/discussions/microsoft/view/81291-exam-ms-100-topic-5-question-73-discussion/
Krayzr 👍 2 Selected: B
NO Authenticator app for Windows (by itself) What a tricky question .
Hchfyvggjg 👍 2 Selected: A
Microsoft Authenticator can be used to sign in to any Microsoft Entra account without using a password. Microsoft Authenticator uses key-based authentication to enable a user credential that is tied to a device, where the device uses a PIN or biometric. Windows Hello for Business uses a similar technology. This authentication technology can be used on any device platform, including mobile. This technology can also be used with any app or website that integrates with Microsoft Authentication Libraries (Microsoft)
Frank9020 👍 3 Selected: B
FIDO2-compliant security keys support passwordless authentication across multiple devices and platforms, including Windows, Android, and iOS.
justITtopics 👍 2 Selected: A
My vote for A since this is a Microsoft technology and they would always use their own first. What is Passworless? => Passwordless authentication methods are more convenient because the password is removed and replaced with something you HAVE or something you are or know. Microsoft Authenticator: The Authenticator App turns any iOS or Android phone into a strong, passwordless credential. Users can sign in to ANY platform or browser by getting a notification to their phone, matching a number displayed on the screen to the one on their phone.
josyexe 👍 2
question 294 is the same but with authenticator app as solution. how is this possible?
APK1 👍 2 Selected: B
There is no Authenticator App for Windows Ans: B
TristanForest 👍 4 Selected: B
FIDO2 key is the only option that will work on all 3 platforms
Nuance 👍 4 Selected: A
I don't believe fido2 keys are supported on iOS and Android
Jeeda8998 👍 2 Selected: B
Chat gpt says b
Tomtom11 👍 1
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless#fido2-security-keys
Bouncy 👍 2 Selected: B
As stated by others, no Authenticator on Windows, hence B
SBGM 👍 4 Selected: B
I think B is correct since there is no Authenticator app for Windows and the question states that the same method must be used on all platforms.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

FIDO2-compliant security keys are a phishing-resistant, standards-based (WebAuthn/CTAP2) passwordless credential that Microsoft Entra ID accepts on Windows, Android, and iOS. The question's binding constraint is one single method across all three device types, and FIDO2 keys satisfy that: the same key can be used over USB-A/USB-C on Windows and over NFC or USB-C on Android and iOS. Microsoft's own passwordless documentation explicitly lists FIDO2 security keys as a supported sign-in method for these platforms, unlike the phone-bound credentials. That makes B the only option that meets both the "passwordless" and the "same method for all devices" requirements.

Why the Other Options Are Wrong

A is wrong because passwordless phone sign-in with the Microsoft Authenticator app is scoped to iOS and Android — there is no Authenticator app credential for passwordless sign-in on Windows, so the requirement of one method for all three platforms fails. C is wrong because multi-factor authentication still depends on a password as the first factor; it is a stronger sign-in, not a passwordless one. D is wrong because Windows Hello for Business is a device-bound Windows credential tied to the TPM/PIN or biometric of a Windows machine, and it cannot be used on Android or iOS at all.

Community Comment Notes

Voting is essentially split (A: 50, B: 50), which shows how often this scenario is misread. Several B voters focus on platform coverage: Frank9020 states that FIDO2-compliant security keys support passwordless authentication on Windows, Android, and iOS, and SBGM argues "there is no Authenticator app for Windows". Krayzr and APK1 reach the same conclusion with the blunt note "NO Authenticator app for Windows (by itself)". Notably, Nuance voted for A while admitting "I don't believe fido2 keys are supported on iOS and Android", and Hchfyvggjg quotes Microsoft material saying Authenticator "can be used on any device platform, including mobile" — true for mobile, but that phrasing does not extend to Windows. josyexe also points out that a nearly identical question elsewhere accepts the Authenticator app, which is exactly why the device list in the stem must drive the answer.

How to Apply This on the Exam

Treat the device list as the deciding data point: whenever a stem says the same passwordless method must serve both desktops and mobiles, FIDO2 security keys are the safe choice, while Authenticator phone sign-in and Windows Hello for Business are each platform-limited.

Official Reference

Exam Strategy

Before choosing a passwordless method, write down the platforms each option actually supports in Microsoft Entra ID — Windows Hello for Business is Windows-only, Authenticator phone sign-in is iOS/Android-only, and FIDO2 keys are cross-platform. Any option that cannot cover every device named in the stem is automatically out, regardless of how "Microsoft-native" it feels.

Frequently Asked Questions

Does the Microsoft Authenticator app support passwordless sign-in on Windows?

No. Passwordless phone sign-in with Microsoft Authenticator is limited to iOS and Android devices, so it cannot serve the Windows devices named in this scenario.

Why can't Windows Hello for Business be used for Android and iOS?

Windows Hello for Business is a device-bound Windows credential that relies on the PC's TPM plus PIN or biometrics, so it is unavailable on Android and iOS.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide