Which Authentication Methods Are Phishing-Resistant MFA for Admins?

Plan, implement, and manage Microsoft Entra Conditional Access Plan, implement, and manage Microsoft Entra user authentication Plan and implement privileged access
Answer Correct answer: A, B, C — Use Windows Hello for Business, FIDO2 security keys, and certificate-based authentication, Microsoft's phishing-resistant MFA for admins.

You have a Microsoft Entra tenant. You need to create a Conditional Access policy to manage administrative access to the tenant. The solution must ensure that administrators are authenticated by using a phishing-resistant multi-factor authentication (MFA) method. Which three authentication methods should you include in the solution? Each correct answer presents a complete solution.

  1. Windows Hello for Business Correct Answer
  2. an FIDO2 security key Correct Answer
  3. certificate-based authentication (multi-factor) Correct Answer
  4. voice call
  5. SMS

Community Votes

ABC
100%

100% of anonymous learners picked answer ABC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The item tests whether you know Microsoft's built-in phishing-resistant MFA strength, not simply what counts as 'MFA' — the trap is treating any second factor (SMS, voice call) as acceptable for administrators.

This SC-300 question asks which three authentication methods qualify as phishing-resistant MFA for a Conditional Access policy guarding administrative access in Microsoft Entra. The page confirms the approved trio — Windows Hello for Business, FIDO2 security keys, and certificate-based authentication (multi-factor) — and explains why SMS and voice call fail the phishing-resistance bar.

Learners often accept SMS or voice call because those methods satisfy a generic 'MFA required' policy, but both are phishable and relayable, so they never meet a phishing-resistant requirement for administrative access.

Community Discussion (4 comments)

Obi_Wan_Jacoby 👍 1 Selected: ABC
Microsoft considers the following as phishing-resistant MFA methods: FIDO2 Security Keys: Hardware keys that authenticate users without passwords. Windows Hello for Business: Uses biometrics (facial recognition or fingerprint) for passwordless login. Certificate-Based Authentication (CBA): Uses digital certificates for multi-factor authentication. These methods provide strong protection against phishing attacks by ensuring that authentication involves secure, non-replicable factors.
Dannyb2000 👍 1 Selected: ABC
Explained in the below link: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-strengths#built-in-authentication-strengths
d1e85d9 👍 1
Can anyone explain why we are not considering Microsoft Authenticator?
Shingie 👍 3 Selected: ABC
Correct Answers: A. Windows Hello for Business B. a FIDO2 security key C. certificate-based authentication (multi-factor) Explanation: To meet the requirement of phishing-resistant multi-factor authentication (MFA) for administrative access, the authentication methods must be resistant to common phishing attacks. Microsoft recognizes the following as phishing-resistant MFA methods: Windows Hello for Business (WHfB) (A) Uses biometrics or PIN tied to a device. Passwordless and resistant to phishing attacks. FIDO2 Security Keys (B) Hardware-based authentication, passwordless, and phishing-resistant. Uses cryptographic keys stored on a physical device. Certificate-Based Authentication (Multi-Factor) (C) Uses a client certificate combined with another authentication factor. More secure than single-factor certificate-based authentication.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra classifies authentication methods into built-in authentication strengths, and the phishing-resistant MFA strength is limited to Windows Hello for Business, FIDO2 security keys, certificate-based authentication (multi-factor), and their Entra equivalents. All three are bound to a device or a cryptographic key pair, so an attacker who captures a one-time code or a phone call cannot replay it against the real tenant. Windows Hello for Business satisfies both possession and inherence requirements through TPM-protected keys and biometrics or PIN. A FIDO2 security key performs origin-bound public-key authentication, which makes credential-relay phishing effectively impossible. Certificate-based authentication (multi-factor) combines a user certificate stored on a protected device with a second factor, and Microsoft explicitly lists it as phishing-resistant. Because the question asks for three complete solutions and options A, B, and C are exactly those three methods, ABC is the defensible verdict.

Why the Other Options Are Wrong

A voice call is an out-of-band one-time code delivered to a phone number — using it as a second factor is legitimate 'MFA' in the generic sense, but it is trivially vulnerable to social-engineering and real-time relay attacks, so it is not phishing-resistant. SMS has the same weakness plus known SIM-swap and interception risks, and Microsoft has been deprecating SMS and voice for exactly this reason. Neither D nor E is bound to a cryptographic secret on a trusted device, so neither can appear in a Conditional Access policy that demands the phishing-resistant MFA authentication strength. Dannyb2000 pointed to Microsoft's authentication-strengths documentation, which lists the phishing-resistant strength tier and makes the SMS/voice exclusion obvious: "Built-in authentication strengths" only places WHfB, FIDO2, and CBA in the resistant tier.

Community Comment Notes

Consensus on the page is strong — every recorded vote selected ABC, and Shingie's answer spells out the same three methods as the Microsoft-recognized phishing-resistant set. Obi_Wan_Jacoby reinforces the reasoning by noting these methods are "hardware keys that authenticate users without passwords" and device-bound biometrics, i.e. they resist credential relay. The one lingering question, raised by d1e85d9 — "Can anyone explain why we are not considering Microsoft Authenticator?" — is a fair one, but Authenticator phone sign-in with number matching is treated by Microsoft as MFA rather than phishing-resistant MFA, because a proxy phishing site can still solicit and relay the approval. That distinction between MFA and phishing-resistant MFA is precisely what this question is testing.

Official Reference

Exam Strategy

Memorize the phishing-resistant MFA tier as a fixed three-item list — Windows Hello for Business, FIDO2 security key, certificate-based authentication (multi-factor) — and treat SMS, voice call, and email OTP as automatic distractors whenever a question says 'phishing-resistant'. Also read the stem carefully: phrases like 'administrative access' plus 'phishing-resistant' together always point at authentication strengths in Conditional Access.

Frequently Asked Questions

Why is Microsoft Authenticator not counted as phishing-resistant MFA here?

Authenticator phone sign-in with number matching is MFA, but a proxy phishing site can still relay the approval in real time, so Microsoft places it below the phishing-resistant strength tier.

Is certificate-based authentication really phishing-resistant?

Yes — Microsoft lists certificate-based authentication (multi-factor) in the built-in phishing-resistant MFA strength, because it relies on a device-bound certificate plus a second factor rather than a transferable code.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide