Enabling Passwordless Sign-in for Workgroup Devices
Your company has a Microsoft Entra tenant named contoso.com and a Microsoft 365 subscription. All users use Windows 10 devices to access Microsoft Office 365 apps. All the devices are in a workgroup. You plan to implement password less sign-in to contoso.com. You need to recommend changes to the infrastructure for the planned implementation. What should you include in the recommendation?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the prerequisite relationship between device management (Hybrid/Cloud Join) and passwordless authentication capabilities like FIDO2 or Windows Hello for Business.
To implement passwordless sign-in in Microsoft Entra ID, devices must be managed by the identity provider. This page explains why joining Windows 10 workgroup devices to the tenant is the required infrastructure change.
Selecting Deploy the Microsoft Authenticator app because users often confuse the user-facing authentication method with the underlying device configuration required to support it.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The core requirement for enabling robust passwordless authentication methods such as Windows Hello for Business or FIDO2 security keys is that the device must be registered with and managed by Microsoft Entra ID. Devices currently in a workgroup lack this integration. Therefore, joining the devices to contoso.com (Microsoft Entra ID) is the necessary infrastructure change to allow the identity service to manage the device's cryptographic keys and trust state.Why the Other Options Are Wrong
Deploying Microsoft Entra Application Proxy is for publishing on-premises apps, not for local device authentication. The Microsoft Entra Connect provisioning agent handles object synchronization from on-premises AD, which does not address the local device configuration needed for passwordless logins. While the Microsoft Authenticator app is a tool used for passwordless login (Push notification), simply installing it on an unjoined workgroup device does not enable the full suite of passwordless features or satisfy the infrastructure requirement for device-based authentication protocols like FIDO2.Community Comment Notes
Community consensus strongly favors option A, noting that joining devices enables the integration with Microsoft’s passwordless authentication options. Some learners mistakenly voted for D, focusing only on the user experience rather than the backend infrastructure necessity. As one commenter noted, the question specifically asks for changes to the infrastructure, which points to the device join status rather than just the client application.Exam Strategy
When a question asks about implementing specific Azure AD/Entra ID features (like Conditional Access or Passwordless), always check if the prerequisites regarding Device Registration or Hybrid Join are met. If devices are in a workgroup, they cannot leverage advanced identity features without first being joined to the directory.
Frequently Asked Questions
Why isn't the Authenticator app enough?
The Authenticator app handles user verification, but passwordless methods like Windows Hello for Business require the device itself to be trusted and registered with Entra ID.
Can workgroup devices use any passwordless method?
Workgroup devices can register for basic MFA, but advanced passwordless features like FIDO2 or Windows Hello for Business require the device to be joined to Entra ID.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →