Which Authentication Method Is Valid for Entra SSPR?
You have a Microsoft Entra tenant. You configure self-service password reset (SSPR) by using the following settings: • Require users to register when signing in: Yes • Number of methods required to reset: 1 What is a valid authentication method available to users?
Community Votes
83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The item tests whether you know the supported SSPR method list and its prerequisites — the trap is picking the mobile app notification because it is a familiar MFA method, even though it depends on the Microsoft Authenticator app being registered with push notifications.
Microsoft Entra self-service password reset (SSPR) supports a defined list of authentication methods, and this question asks which one is valid when registration is required at sign-in and only one method is needed to reset. The page confirms that an email address outside your organization is a valid SSPR method and explains why Windows Hello PIN, smartcard, and a mobile app notification are not the intended answer.
Choosing 'a mobile app notification' simply because it appears in Entra authentication method lists; it is an SSPR method only when the Authenticator app is installed and registered with push notifications, so it is not the unconditionally valid choice the scenario asks for.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
With SSPR configured to require registration at sign-in and only 'Number of methods required to reset: 1', the question asks which method a user can actually authenticate with during a reset. An email address outside your organization is a supported SSPR authentication method in Microsoft Entra: users may register a personal/non-corporate address so they can still reset a password when they cannot reach their work mailbox. It needs no device, no app install, and no MFA registration, so it is valid under the minimal settings the scenario gives. That is why the exam key marks D, and roughly 83% of the community votes agree. The word 'valid' is the pivot — the exam wants the method that stands on its own with only the stated configuration.Why the Other Options Are Wrong
A Windows Hello PIN is a Windows sign-in credential, and a smartcard is a physical certificate-based logon device; neither can be registered as an SSPR method, so both are eliminated immediately. A mobile app notification is genuinely listed among SSPR methods in Microsoft documentation, but it depends on the user having the Microsoft Authenticator app installed and registered with push notifications, and Microsoft's 'Mobile app and SSPR' guidance adds further considerations when the tenant has not migrated to the centralized Authentication methods policy. Because the scenario never establishes that app-based prerequisite, the notification method is not the method the item treats as unconditionally available. Several commenters rightly note the question is loosely worded, since with a properly enabled mobile app policy the notification could also work — in the exam's framing, email remains the cleaner answer.Community Comment Notes
YesPlease argued that "You guys are reading this question all wrong", reasoning that the question refers to the SSPR method list, which does include mobile app notification. JFROG reached the opposite conclusion and cited the Microsoft doc section "Mobile app and SSPR", which is exactly where the conditional caveats on the Authenticator app originate. Sunth65 summarized the practical ordering by saying "First priority is mobile app code", while mert123 simply stated "d is correct". Another commenter complained that the same question appears repeatedly with different answers — a fair warning that when an item is this ambiguous you should fall back on which method needs the fewest prerequisites.Official Reference
Exam Strategy
When an SSPR item asks which method is 'valid', rank the options by prerequisites rather than by familiarity: physical/Windows-only credentials are never SSPR methods, app-based methods need the Authenticator app registered, and email or phone methods work with registration alone. Read the settings block carefully — the number of required methods and the registration prompt usually exist to rule out options that depend on MFA or device state.
Frequently Asked Questions
Is a mobile app notification also a valid SSPR method in Entra?
It is on the SSPR method list, but it requires the Microsoft Authenticator app to be installed and registered with push notifications, which the scenario never guarantees.
Why is an email outside the organization accepted for password reset?
Microsoft Entra lets users register a personal email as an SSPR method so they can reset a password even when they cannot access the corporate mailbox.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →