Which Authentication Method Is Valid for Entra SSPR?

Answer Correct answer: D — an email to an address outside your organization is a valid Microsoft Entra SSPR authentication method when only one reset method is required.

You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings: • Require users to register when signing in: Yes • Number of methods required to reset: 1 What is a valid authentication method available to users?

  1. a Windows Hello PIN
  2. a smartcard
  3. a mobile app notification
  4. an email to an address outside your organization Correct Answer

Community Votes

D
83%
C
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The item tests whether you know the supported SSPR method list and its prerequisites — the trap is picking the mobile app notification because it is a familiar MFA method, even though it depends on the Microsoft Authenticator app being registered with push notifications.

Microsoft Entra self-service password reset (SSPR) supports a defined list of authentication methods, and this question asks which one is valid when registration is required at sign-in and only one method is needed to reset. The page confirms that an email address outside your organization is a valid SSPR method and explains why Windows Hello PIN, smartcard, and a mobile app notification are not the intended answer.

Choosing 'a mobile app notification' simply because it appears in Entra authentication method lists; it is an SSPR method only when the Authenticator app is installed and registered with push notifications, so it is not the unconditionally valid choice the scenario asks for.

Community Discussion (5 comments)

YesPlease 👍 1 Selected: C
Answer C) a mobile app notification You guys are reading this question all wrong. This is asking about SSPR "authentication" and although it is stating that you must register at least 1 method, it does not mean that it is the only method that is enabled. The following authentication methods are available for SSPR: - Mobile app notification (this is valid if they setup more than one method to authenticate) - Mobile app code (valid for one method registration only scenario) - Email (*Has to be to their company email address and not external) - Mobile phone - Office phone (available only for tenants with paid subscriptions) - Security questions https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks#authentication-methods
59e8fdb 👍 1 Selected: D
Again the same question in the 1 last questions 3 questions are same with the same context completely different answers
JFROG 👍 1 Selected: D
The catch in this question is the number of methods required: Check https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sspr-howitworks. "Mobile app and SSPR When using a mobile app as a method for password reset, like Microsoft Authenticator, the following considerations apply if an organization hasn't migrated to the centralized Authentication methods policy: When administrators require one method be used to reset a password, verification code is the only option available. When administrators require two methods be used to reset a password, users are able to use notification OR verification code in addition to any other enabled methods." My choice will be D
Sunth65 👍 1 Selected: D
First priority is mobile app code, second priority is an email to an address outside your organization
mert123 👍 2 Selected: D
d is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

With SSPR configured to require registration at sign-in and only 'Number of methods required to reset: 1', the question asks which method a user can actually authenticate with during a reset. An email address outside your organization is a supported SSPR authentication method in Microsoft Entra: users may register a personal/non-corporate address so they can still reset a password when they cannot reach their work mailbox. It needs no device, no app install, and no MFA registration, so it is valid under the minimal settings the scenario gives. That is why the exam key marks D, and roughly 83% of the community votes agree. The word 'valid' is the pivot — the exam wants the method that stands on its own with only the stated configuration.

Why the Other Options Are Wrong

A Windows Hello PIN is a Windows sign-in credential, and a smartcard is a physical certificate-based logon device; neither can be registered as an SSPR method, so both are eliminated immediately. A mobile app notification is genuinely listed among SSPR methods in Microsoft documentation, but it depends on the user having the Microsoft Authenticator app installed and registered with push notifications, and Microsoft's 'Mobile app and SSPR' guidance adds further considerations when the tenant has not migrated to the centralized Authentication methods policy. Because the scenario never establishes that app-based prerequisite, the notification method is not the method the item treats as unconditionally available. Several commenters rightly note the question is loosely worded, since with a properly enabled mobile app policy the notification could also work — in the exam's framing, email remains the cleaner answer.

Community Comment Notes

YesPlease argued that "You guys are reading this question all wrong", reasoning that the question refers to the SSPR method list, which does include mobile app notification. JFROG reached the opposite conclusion and cited the Microsoft doc section "Mobile app and SSPR", which is exactly where the conditional caveats on the Authenticator app originate. Sunth65 summarized the practical ordering by saying "First priority is mobile app code", while mert123 simply stated "d is correct". Another commenter complained that the same question appears repeatedly with different answers — a fair warning that when an item is this ambiguous you should fall back on which method needs the fewest prerequisites.

Official Reference

Exam Strategy

When an SSPR item asks which method is 'valid', rank the options by prerequisites rather than by familiarity: physical/Windows-only credentials are never SSPR methods, app-based methods need the Authenticator app registered, and email or phone methods work with registration alone. Read the settings block carefully — the number of required methods and the registration prompt usually exist to rule out options that depend on MFA or device state.

Frequently Asked Questions

Is a mobile app notification also a valid SSPR method in Entra?

It is on the SSPR method list, but it requires the Microsoft Authenticator app to be installed and registered with push notifications, which the scenario never guarantees.

Why is an email outside the organization accepted for password reset?

Microsoft Entra lets users register a personal email as an SSPR method so they can reset a password even when they cannot access the corporate mailbox.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide