Which two auth methods enable passwordless Entra sign-in to a Linux VM?
You have an Azure subscription. The subscription contains a virtual machine named VM1 that runs Linux. You need to configure enhanced security for VM1. The solution must meet the following requirements: • Ensure that users can sign in to VM1 by using their Microsoft Entra credentials. • Ensure that users authenticate by using multi-factor out-of-band. • Prevent users from signing in to VM1 by using passwords. Which two authentication methods can you include in the solution? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Community Votes
100% of anonymous learners picked answer AB. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which Entra authentication methods are both passwordless and supported for signing in to an Azure Linux VM, and the trap is picking SMS simply because it is an out-of-band second factor.
For an Azure Linux VM that must accept Microsoft Entra credentials, out-of-band MFA and no passwords, the workable authentication methods are the Microsoft Authenticator app and FIDO2 security keys. This page confirms answer A, B and explains why SMS, Temporary Access Pass and Windows Hello for Business fail the three stated requirements.
Many candidates pick SMS (D) because it is genuinely out-of-band, but SMS is only a second factor layered on a password and is not a passwordless method for VM sign-in, so it cannot satisfy the 'prevent signing in with passwords' requirement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The scenario requires three things at once: sign-in to VM1 with Microsoft Entra credentials, out-of-band multi-factor authentication, and no password anywhere in the flow. The Microsoft Authenticator app (A) supports passwordless phone sign-in and delivers the approval prompt out-of-band to a separate registered device, so an attacker who has only the VM session or a password cannot complete it. FIDO2 security keys (B) are likewise a supported passwordless method for Entra ID sign-in on Azure VMs: the user presents the key instead of a password, the key-bound Entra credential identifies the user, and the possession factor satisfies the MFA requirement. Neither method ever transmits a reusable password to VM1, which is exactly what the third bullet forbids. That is why A and B form the two valid, complete solutions the question asks for.Why the Other Options Are Wrong
Temporary Access Pass (C) is a time-limited onboarding and recovery code used to bootstrap a user into passwordless methods or register a credential; it is deliberately not a standing sign-in method for routine VM access. SMS (D) is out-of-band, but it functions only as an additional verification step on top of a password-based first factor, so it directly contradicts the requirement to prevent password sign-in, and it is not a supported primary method for Azure VM sign-in. Windows Hello for Business (E) is a Windows client technology tied to Windows Hello-capable hardware and the Windows sign-in experience; VM1 runs Linux, so it cannot be included in this solution at all. Each of C, D and E therefore fails at least one of the three stated requirements.Community Comment Notes
All three commenters converged on the same verdict without dissent in the 100-vote record. Matt19 put it plainly, writing that the "MS Authenticator app allows passwords sign-ins and FIDO2 is for sure correct" — the first fragment is a typo for passwordless sign-in, which is precisely the property both methods share. TRN80 endorsed that reasoning, stating that "Matt19 is correct the answer should be A+B", and 59e8fdb added the short confirmation "A+B for sure!". The consensus is useful because it highlights the discriminating criterion exam writers rely on here: the method must be passwordless AND validated for Azure VM sign-in, not merely a second factor. No commenter attempted to defend SMS or Temporary Access Pass, which matches the analysis above.Answer Statement Recap
Correct answer: A, B — include the Microsoft Authenticator app and FIDO2 security keys in the VM1 solution.Official Reference
Exam Strategy
Read the three bullets as hard AND conditions and test every option against all of them, not just the one that stands out. Out-of-band and passwordless are not synonyms on this exam: SMS is out-of-band yet password-based, while FIDO2 and Microsoft Authenticator are both passwordless and MFA-capable for Azure VM sign-in.
Frequently Asked Questions
Why is SMS (D) wrong when it is clearly an out-of-band method?
SMS is out-of-band but works only as a second factor on top of a password, and it is not supported as a primary sign-in method for Azure VMs, so it fails the no-password requirement.
Why can't Temporary Access Pass (C) be part of the VM1 sign-in solution?
A Temporary Access Pass is a time-limited code for onboarding and credential recovery, not a standing passwordless method users would authenticate to a Linux VM with.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →