Which passwordless method works on Windows, Android, and iOS?
You have a Microsoft 365 subscription. You need to implement a passwordless authentication solution that supports the following device types: • Windows • Android • iOS The solution must use the same authentication method for all devices. Which authentication method should you use?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests platform support for each passwordless credential in Microsoft Entra ID; the trap is assuming Microsoft Authenticator works everywhere, when its passwordless phone sign-in credential exists only on iOS and Android.
This MS-102 question asks which single passwordless authentication method covers Windows, Android, and iOS devices at the same time. FIDO2-compliant security keys are confirmed as the answer because they are the only listed credential supported across all three platforms.
Picking the Microsoft Authenticator app (A) because it is Microsoft's flagship passwordless option — but its phone sign-in credential is issued only on iOS and Android, so Windows devices are left without a matching passwordless method.
Community Discussion (13 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
FIDO2-compliant security keys are a phishing-resistant, standards-based (WebAuthn/CTAP2) passwordless credential that Microsoft Entra ID accepts on Windows, Android, and iOS. The question's binding constraint is one single method across all three device types, and FIDO2 keys satisfy that: the same key can be used over USB-A/USB-C on Windows and over NFC or USB-C on Android and iOS. Microsoft's own passwordless documentation explicitly lists FIDO2 security keys as a supported sign-in method for these platforms, unlike the phone-bound credentials. That makes B the only option that meets both the "passwordless" and the "same method for all devices" requirements.Why the Other Options Are Wrong
A is wrong because passwordless phone sign-in with the Microsoft Authenticator app is scoped to iOS and Android — there is no Authenticator app credential for passwordless sign-in on Windows, so the requirement of one method for all three platforms fails. C is wrong because multi-factor authentication still depends on a password as the first factor; it is a stronger sign-in, not a passwordless one. D is wrong because Windows Hello for Business is a device-bound Windows credential tied to the TPM/PIN or biometric of a Windows machine, and it cannot be used on Android or iOS at all.Community Comment Notes
Voting is essentially split (A: 50, B: 50), which shows how often this scenario is misread. Several B voters focus on platform coverage: Frank9020 states that FIDO2-compliant security keys support passwordless authentication on Windows, Android, and iOS, and SBGM argues "there is no Authenticator app for Windows". Krayzr and APK1 reach the same conclusion with the blunt note "NO Authenticator app for Windows (by itself)". Notably, Nuance voted for A while admitting "I don't believe fido2 keys are supported on iOS and Android", and Hchfyvggjg quotes Microsoft material saying Authenticator "can be used on any device platform, including mobile" — true for mobile, but that phrasing does not extend to Windows. josyexe also points out that a nearly identical question elsewhere accepts the Authenticator app, which is exactly why the device list in the stem must drive the answer.How to Apply This on the Exam
Treat the device list as the deciding data point: whenever a stem says the same passwordless method must serve both desktops and mobiles, FIDO2 security keys are the safe choice, while Authenticator phone sign-in and Windows Hello for Business are each platform-limited.Official Reference
Exam Strategy
Before choosing a passwordless method, write down the platforms each option actually supports in Microsoft Entra ID — Windows Hello for Business is Windows-only, Authenticator phone sign-in is iOS/Android-only, and FIDO2 keys are cross-platform. Any option that cannot cover every device named in the stem is automatically out, regardless of how "Microsoft-native" it feels.
Frequently Asked Questions
Does the Microsoft Authenticator app support passwordless sign-in on Windows?
No. Passwordless phone sign-in with Microsoft Authenticator is limited to iOS and Android devices, so it cannot serve the Windows devices named in this scenario.
Why can't Windows Hello for Business be used for Android and iOS?
Windows Hello for Business is a device-bound Windows credential that relies on the PC's TPM plus PIN or biometrics, so it is unavailable on Android and iOS.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →