Valid SSPR Authentication Method When Only One Reset Method Is Required
You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings: • Require users to register when signing in: Yes • Number of methods required to reset: 1 What is a valid authentication method available to users?
Community Votes
62% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the SSPR method catalog plus the push-notification caveat: when 'Number of methods required to reset' is 1, the Microsoft Authenticator can only return a verification code, so mobile app notification is unavailable and email to an external address remains valid.
Self-service password reset (SSPR) in Microsoft Entra ID supports a fixed set of authentication methods, and the tenant here is configured so users must register at sign-in with only one method required to reset. This page establishes that under a one-method configuration the valid choice is an email verification code sent to an address outside your organization, not a mobile app notification.
Choosing 'a mobile app notification' (B) because it is a famous SSPR and MFA option — but with only one required reset method Microsoft allows just the Authenticator's verification code, so notification cannot complete the reset here.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
With SSPR enabled, 'Require users to register when signing in' set to Yes, and 'Number of methods required to reset' set to 1, each user needs exactly one working verification path — and an email to an address outside your organization qualifies. Microsoft's SSPR method list includes Email, which delivers a verification code to an alternate address the user controls and can still reach while locked out of the tenant. Because a single method is sufficient, one registered external email address lets the user reset without a second method ever being prompted. An address outside the organization is the intended target for that method: the reset code must be retrievable by someone who cannot sign in, which the mailbox behind the forgotten password is not. Choosing A therefore matches both the documented method inventory and the specific one-method setting configured in the scenario.Why the Other Options Are Wrong
Option B (mobile app notification) fails directly on the question's configuration: Microsoft's SSPR guidance states that when administrators require one method be used, 'verification code is the only option available' for the Authenticator app, and notification becomes selectable only when two methods are required. Option C (smartcard) is not an SSPR method at all — smartcards are a sign-in credential, while SSPR is limited to mobile app notification, mobile app code, email, mobile phone, office phone, and security questions. Option D (email to an address in your organization) is excluded for the same reason the external address is required: a work mailbox inside the tenant is the resource protected by the password being reset, so the user cannot open it to collect the code while locked out. Option A is the only choice that both exists as an SSPR method and survives the one-method restriction.Community Comment Notes
nicolaslindt cited the SSPR documentation and reasoned that 'verification code is the only option available' for the app path when a single method is required, which supports A over B. rvln7 repeated the same documentation sentence and added the reverse case — with two methods required, users 'are able to use notification OR verification code' — confirming notification is gated behind the two-method setting. Btn26 argued for option B, calling mobile app notification a commonly used SSPR verification method, which is true in general but not under this tenant's one-method configuration. The vote split, with A clearly ahead of B, reflects exactly that notification-versus-code confusion among learners.Official Reference
Exam Strategy
Read the SSPR settings block before the options — the 'number of methods required' value flips which Authenticator capability is usable, and that single number decides between A and B. Then eliminate anything that is not in the SSPR method list (smartcards, FIDO keys) and anything that sends the code to a mailbox the locked-out user cannot open.
Frequently Asked Questions
Why is mobile app notification invalid when only one SSPR method is required?
Microsoft gates the Authenticator push behind the two-method setting: with one required method, verification code is the only app option, so notification cannot complete the reset.
Can a user register a work email address for SSPR email verification?
No. The email method targets an alternate address the user can reach while locked out; an in-organization mailbox is the resource protected by the forgotten password.
Is a smartcard an SSPR authentication method?
No. Smartcards are a sign-in credential, not part of the SSPR set (mobile app notification, mobile app code, email, mobile phone, office phone, security questions).
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →