Enabling Passwordless Sign-in for Workgroup Devices

Answer Correct answer: A — Join all the devices to contoso.com to enable device management required for passwordless authentication.

Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?

  1. Join all the devices to contoso.com. Correct Answer
  2. Deploy Microsoft Entra Application Proxy.
  3. Deploy the Microsoft Entra Connect provisioning agent.
  4. Deploy the Microsoft Authenticator app.

Community Votes

A
80%
D
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the prerequisite relationship between device management (Hybrid/Cloud Join) and passwordless authentication capabilities like FIDO2 or Windows Hello for Business.

To implement passwordless sign-in in Microsoft Entra ID, devices must be managed by the identity provider. This page explains why joining Windows 10 workgroup devices to the tenant is the required infrastructure change.

Selecting Deploy the Microsoft Authenticator app because users often confuse the user-facing authentication method with the underlying device configuration required to support it.

Community Discussion (5 comments)

atre_01 👍 7 Selected: A
This question is equal to question number 268 where most voted answer is A
BigO76 👍 1 Selected: A
Joining devices to Microsoft Entra (Azure AD) enables integration with Microsoft’s passwordless authentication options. It not Microsoft Authenticator app here because the infrastructure requirement here focuses on enabling passwordless authentication on Windows 10 devices, which requires joining the devices to Microsoft Entra (Azure AD). It is quite specific in the question.
Ody 👍 1 Selected: D
Non-joined devices can access your tenants Microsoft 365 apps, but there may be a difference in what data can be accessed.
AdamRachel 👍 1
I think here the difference is that you implement password-less sign-in.
GetEsn 👍 1 Selected: D
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The core requirement for enabling robust passwordless authentication methods such as Windows Hello for Business or FIDO2 security keys is that the device must be registered with and managed by Microsoft Entra ID. Devices currently in a workgroup lack this integration. Therefore, joining the devices to contoso.com (Microsoft Entra ID) is the necessary infrastructure change to allow the identity service to manage the device's cryptographic keys and trust state.

Why the Other Options Are Wrong

Deploying Microsoft Entra Application Proxy is for publishing on-premises apps, not for local device authentication. The Microsoft Entra Connect provisioning agent handles object synchronization from on-premises AD, which does not address the local device configuration needed for passwordless logins. While the Microsoft Authenticator app is a tool used for passwordless login (Push notification), simply installing it on an unjoined workgroup device does not enable the full suite of passwordless features or satisfy the infrastructure requirement for device-based authentication protocols like FIDO2.

Community Comment Notes

Community consensus strongly favors option A, noting that joining devices enables the integration with Microsoft’s passwordless authentication options. Some learners mistakenly voted for D, focusing only on the user experience rather than the backend infrastructure necessity. As one commenter noted, the question specifically asks for changes to the infrastructure, which points to the device join status rather than just the client application.

Exam Strategy

When a question asks about implementing specific Azure AD/Entra ID features (like Conditional Access or Passwordless), always check if the prerequisites regarding Device Registration or Hybrid Join are met. If devices are in a workgroup, they cannot leverage advanced identity features without first being joined to the directory.

Frequently Asked Questions

Why isn't the Authenticator app enough?

The Authenticator app handles user verification, but passwordless methods like Windows Hello for Business require the device itself to be trusted and registered with Entra ID.

Can workgroup devices use any passwordless method?

Workgroup devices can register for basic MFA, but advanced passwordless features like FIDO2 or Windows Hello for Business require the device to be joined to Entra ID.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide