Which Authentication Methods Are Phishing-Resistant MFA for Admins?
You have a Microsoft Entra tenant. You need to create a Conditional Access policy to manage administrative access to the tenant. The solution must ensure that administrators are authenticated by using a phishing-resistant multi-factor authentication (MFA) method. Which three authentication methods should you include in the solution? Each correct answer presents a complete solution.
Community Votes
100% of anonymous learners picked answer ABC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The item tests whether you know Microsoft's built-in phishing-resistant MFA strength, not simply what counts as 'MFA' — the trap is treating any second factor (SMS, voice call) as acceptable for administrators.
This SC-300 question asks which three authentication methods qualify as phishing-resistant MFA for a Conditional Access policy guarding administrative access in Microsoft Entra. The page confirms the approved trio — Windows Hello for Business, FIDO2 security keys, and certificate-based authentication (multi-factor) — and explains why SMS and voice call fail the phishing-resistance bar.
Learners often accept SMS or voice call because those methods satisfy a generic 'MFA required' policy, but both are phishable and relayable, so they never meet a phishing-resistant requirement for administrative access.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra classifies authentication methods into built-in authentication strengths, and the phishing-resistant MFA strength is limited to Windows Hello for Business, FIDO2 security keys, certificate-based authentication (multi-factor), and their Entra equivalents. All three are bound to a device or a cryptographic key pair, so an attacker who captures a one-time code or a phone call cannot replay it against the real tenant. Windows Hello for Business satisfies both possession and inherence requirements through TPM-protected keys and biometrics or PIN. A FIDO2 security key performs origin-bound public-key authentication, which makes credential-relay phishing effectively impossible. Certificate-based authentication (multi-factor) combines a user certificate stored on a protected device with a second factor, and Microsoft explicitly lists it as phishing-resistant. Because the question asks for three complete solutions and options A, B, and C are exactly those three methods, ABC is the defensible verdict.Why the Other Options Are Wrong
A voice call is an out-of-band one-time code delivered to a phone number — using it as a second factor is legitimate 'MFA' in the generic sense, but it is trivially vulnerable to social-engineering and real-time relay attacks, so it is not phishing-resistant. SMS has the same weakness plus known SIM-swap and interception risks, and Microsoft has been deprecating SMS and voice for exactly this reason. Neither D nor E is bound to a cryptographic secret on a trusted device, so neither can appear in a Conditional Access policy that demands the phishing-resistant MFA authentication strength. Dannyb2000 pointed to Microsoft's authentication-strengths documentation, which lists the phishing-resistant strength tier and makes the SMS/voice exclusion obvious: "Built-in authentication strengths" only places WHfB, FIDO2, and CBA in the resistant tier.Community Comment Notes
Consensus on the page is strong — every recorded vote selected ABC, and Shingie's answer spells out the same three methods as the Microsoft-recognized phishing-resistant set. Obi_Wan_Jacoby reinforces the reasoning by noting these methods are "hardware keys that authenticate users without passwords" and device-bound biometrics, i.e. they resist credential relay. The one lingering question, raised by d1e85d9 — "Can anyone explain why we are not considering Microsoft Authenticator?" — is a fair one, but Authenticator phone sign-in with number matching is treated by Microsoft as MFA rather than phishing-resistant MFA, because a proxy phishing site can still solicit and relay the approval. That distinction between MFA and phishing-resistant MFA is precisely what this question is testing.Official Reference
Exam Strategy
Memorize the phishing-resistant MFA tier as a fixed three-item list — Windows Hello for Business, FIDO2 security key, certificate-based authentication (multi-factor) — and treat SMS, voice call, and email OTP as automatic distractors whenever a question says 'phishing-resistant'. Also read the stem carefully: phrases like 'administrative access' plus 'phishing-resistant' together always point at authentication strengths in Conditional Access.
Frequently Asked Questions
Why is Microsoft Authenticator not counted as phishing-resistant MFA here?
Authenticator phone sign-in with number matching is MFA, but a proxy phishing site can still relay the approval in real time, so Microsoft places it below the phishing-resistant strength tier.
Is certificate-based authentication really phishing-resistant?
Yes — Microsoft lists certificate-based authentication (multi-factor) in the built-in phishing-resistant MFA strength, because it relies on a device-bound certificate plus a second factor rather than a transferable code.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →