Which two auth methods enable passwordless Entra sign-in to a Linux VM?

Plan, implement, and manage Microsoft Entra user authentication
Answer Correct answer: A, B — Add the Microsoft Authenticator app and FIDO2 security keys so users sign in to Linux VM1 with Entra credentials, out-of-band MFA, and no password.

You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Linux. You need to configure enhanced security for VM1. The solution must meet the following requirements: • Ensure that users can sign in to VM1 by using their Microsoft Entra credentials. • Ensure that users authenticate by using multi-factor out-of-band. • Prevent users from signing in to VM1 by using passwords. Which two authentication methods can you include in the solution? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  1. the Microsoft Authenticator app Correct Answer
  2. FIDO2 security keys Correct Answer
  3. Temporary Access Pass
  4. SMS
  5. Windows Hello for Business

Community Votes

AB
100%

100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests which Entra authentication methods are both passwordless and supported for signing in to an Azure Linux VM, and the trap is picking SMS simply because it is an out-of-band second factor.

For an Azure Linux VM that must accept Microsoft Entra credentials, out-of-band MFA and no passwords, the workable authentication methods are the Microsoft Authenticator app and FIDO2 security keys. This page confirms answer A, B and explains why SMS, Temporary Access Pass and Windows Hello for Business fail the three stated requirements.

Many candidates pick SMS (D) because it is genuinely out-of-band, but SMS is only a second factor layered on a password and is not a passwordless method for VM sign-in, so it cannot satisfy the 'prevent signing in with passwords' requirement.

Community Discussion (3 comments)

59e8fdb 👍 1 Selected: AB
A+B for sure!
TRN80 👍 2 Selected: AB
Matt19 is correct the answer should be A+B
Matt19 👍 3 Selected: AB
A&B - MS Authenticator app allows passwords sign-ins and FIDO2 is for sure correct.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario requires three things at once: sign-in to VM1 with Microsoft Entra credentials, out-of-band multi-factor authentication, and no password anywhere in the flow. The Microsoft Authenticator app (A) supports passwordless phone sign-in and delivers the approval prompt out-of-band to a separate registered device, so an attacker who has only the VM session or a password cannot complete it. FIDO2 security keys (B) are likewise a supported passwordless method for Entra ID sign-in on Azure VMs: the user presents the key instead of a password, the key-bound Entra credential identifies the user, and the possession factor satisfies the MFA requirement. Neither method ever transmits a reusable password to VM1, which is exactly what the third bullet forbids. That is why A and B form the two valid, complete solutions the question asks for.

Why the Other Options Are Wrong

Temporary Access Pass (C) is a time-limited onboarding and recovery code used to bootstrap a user into passwordless methods or register a credential; it is deliberately not a standing sign-in method for routine VM access. SMS (D) is out-of-band, but it functions only as an additional verification step on top of a password-based first factor, so it directly contradicts the requirement to prevent password sign-in, and it is not a supported primary method for Azure VM sign-in. Windows Hello for Business (E) is a Windows client technology tied to Windows Hello-capable hardware and the Windows sign-in experience; VM1 runs Linux, so it cannot be included in this solution at all. Each of C, D and E therefore fails at least one of the three stated requirements.

Community Comment Notes

All three commenters converged on the same verdict without dissent in the 100-vote record. Matt19 put it plainly, writing that the "MS Authenticator app allows passwords sign-ins and FIDO2 is for sure correct" — the first fragment is a typo for passwordless sign-in, which is precisely the property both methods share. TRN80 endorsed that reasoning, stating that "Matt19 is correct the answer should be A+B", and 59e8fdb added the short confirmation "A+B for sure!". The consensus is useful because it highlights the discriminating criterion exam writers rely on here: the method must be passwordless AND validated for Azure VM sign-in, not merely a second factor. No commenter attempted to defend SMS or Temporary Access Pass, which matches the analysis above.

Answer Statement Recap

Correct answer: A, B — include the Microsoft Authenticator app and FIDO2 security keys in the VM1 solution.

Official Reference

Exam Strategy

Read the three bullets as hard AND conditions and test every option against all of them, not just the one that stands out. Out-of-band and passwordless are not synonyms on this exam: SMS is out-of-band yet password-based, while FIDO2 and Microsoft Authenticator are both passwordless and MFA-capable for Azure VM sign-in.

Frequently Asked Questions

Why is SMS (D) wrong when it is clearly an out-of-band method?

SMS is out-of-band but works only as a second factor on top of a password, and it is not supported as a primary sign-in method for Azure VMs, so it fails the no-password requirement.

Why can't Temporary Access Pass (C) be part of the VM1 sign-in solution?

A Temporary Access Pass is a time-limited code for onboarding and credential recovery, not a standing passwordless method users would authenticate to a Linux VM with.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide