Valid SSPR Authentication Method When Only One Reset Method Is Required

Plan, implement, and manage Microsoft Entra user authentication
Answer Correct answer: A — With SSPR set to require one reset method, users can verify with an email code sent to a personal address outside your organization.

You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings: • Require users to register when signing in: Yes • Number of methods required to reset: 1 What is a valid authentication method available to users?

  1. an email to an address outside your organization Correct Answer
  2. a mobile app notification
  3. a smartcard
  4. an email to an address in your organization

Community Votes

A
62%
B
38%

62% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the SSPR method catalog plus the push-notification caveat: when 'Number of methods required to reset' is 1, the Microsoft Authenticator can only return a verification code, so mobile app notification is unavailable and email to an external address remains valid.

Self-service password reset (SSPR) in Microsoft Entra ID supports a fixed set of authentication methods, and the tenant here is configured so users must register at sign-in with only one method required to reset. This page establishes that under a one-method configuration the valid choice is an email verification code sent to an address outside your organization, not a mobile app notification.

Choosing 'a mobile app notification' (B) because it is a famous SSPR and MFA option — but with only one required reset method Microsoft allows just the Authenticator's verification code, so notification cannot complete the reset here.

Community Discussion (3 comments)

rvln7 👍 1 Selected: A
"When administrators require one method be used to reset a password, verification code is the only option available. When administrators require two methods be used to reset a password, users are able to use notification OR verification code in addition to any other enabled methods." https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks?source=recommendations#authentication-methods so we can NOT use a mobile app notification here and SSPR does not allow sending reset codes to internal email addresses due to security risks. so the right answer is A. Users can receive a verification code via an external email guys, please stop guessing answers, read the documentation first
nicolaslindt 👍 4 Selected: A
When administrators require one method be used to reset a password, verification code is the only option available for the app option. (https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks). The following authentication methods are available for SSPR: Mobile app notification Mobile app code Email Mobile phone Office phone (available only for tenants with paid subscriptions) Security questions
Btn26 👍 3 Selected: B
For self-service password reset (SSPR) in Microsoft Entra, a valid authentication method available to users is a mobile app notification (Option B)[1](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks)[2](https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr). This method is commonly used for verifying user identity during the password reset process. [1](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks): [Microsoft Learn - Self-service password reset deep dive](https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks) [2](https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr): [Microsoft Learn - Enable Microsoft Entra self-service password reset](https://learn.microsoft.com/en-us/entra/identity/authentication/tutorial-enable-sspr)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

With SSPR enabled, 'Require users to register when signing in' set to Yes, and 'Number of methods required to reset' set to 1, each user needs exactly one working verification path — and an email to an address outside your organization qualifies. Microsoft's SSPR method list includes Email, which delivers a verification code to an alternate address the user controls and can still reach while locked out of the tenant. Because a single method is sufficient, one registered external email address lets the user reset without a second method ever being prompted. An address outside the organization is the intended target for that method: the reset code must be retrievable by someone who cannot sign in, which the mailbox behind the forgotten password is not. Choosing A therefore matches both the documented method inventory and the specific one-method setting configured in the scenario.

Why the Other Options Are Wrong

Option B (mobile app notification) fails directly on the question's configuration: Microsoft's SSPR guidance states that when administrators require one method be used, 'verification code is the only option available' for the Authenticator app, and notification becomes selectable only when two methods are required. Option C (smartcard) is not an SSPR method at all — smartcards are a sign-in credential, while SSPR is limited to mobile app notification, mobile app code, email, mobile phone, office phone, and security questions. Option D (email to an address in your organization) is excluded for the same reason the external address is required: a work mailbox inside the tenant is the resource protected by the password being reset, so the user cannot open it to collect the code while locked out. Option A is the only choice that both exists as an SSPR method and survives the one-method restriction.

Community Comment Notes

nicolaslindt cited the SSPR documentation and reasoned that 'verification code is the only option available' for the app path when a single method is required, which supports A over B. rvln7 repeated the same documentation sentence and added the reverse case — with two methods required, users 'are able to use notification OR verification code' — confirming notification is gated behind the two-method setting. Btn26 argued for option B, calling mobile app notification a commonly used SSPR verification method, which is true in general but not under this tenant's one-method configuration. The vote split, with A clearly ahead of B, reflects exactly that notification-versus-code confusion among learners.

Official Reference

Exam Strategy

Read the SSPR settings block before the options — the 'number of methods required' value flips which Authenticator capability is usable, and that single number decides between A and B. Then eliminate anything that is not in the SSPR method list (smartcards, FIDO keys) and anything that sends the code to a mailbox the locked-out user cannot open.

Frequently Asked Questions

Why is mobile app notification invalid when only one SSPR method is required?

Microsoft gates the Authenticator push behind the two-method setting: with one required method, verification code is the only app option, so notification cannot complete the reset.

Can a user register a work email address for SSPR email verification?

No. The email method targets an alternate address the user can reach while locked out; an in-organization mailbox is the resource protected by the forgotten password.

Is a smartcard an SSPR authentication method?

No. Smartcards are a sign-in credential, not part of the SSPR set (mobile app notification, mobile app code, email, mobile phone, office phone, security questions).

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide