How Many Factors Does Azure AD Multi-Factor Authentication Require?
When you enable Azure AD Multi-Factor Authentication (MFA), how many factors are required for authentication?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the baseline definition of MFA in Microsoft Entra ID — two factors from different categories — while the trap is confusing the categories MFA can draw from with the number actually enforced.
Azure AD Multi-Factor Authentication (MFA) requires exactly two factors at sign-in: the user's password plus a second verification method. This SC-900 page confirms that option B is the correct answer and explains why factor counts of 1, 3, and 4 are wrong.
Picking 3 (option C) because MFA is often taught with three factor categories (something you know, something you have, something you are); Azure AD MFA still only demands two at sign-in.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Multi-factor authentication is defined as authentication using two or more different categories of evidence, and Azure AD (Microsoft Entra ID) MFA enforces exactly two factors by default. The user proves identity with something they know (a password) and then proves it again with something they have (Microsoft Authenticator push, an SMS/voice code, a FIDO2 key) or something they are (biometric). Option B (2) matches this definition and the service behavior tested by SC-900. Enabling MFA is precisely what upgrades a single-factor password sign-in to a two-factor one, so the number cannot be 1.Why the Other Options Are Wrong
Option A (1) describes single-factor authentication — a password alone — which is exactly what enabling MFA is designed to replace. Options C (3) and D (4) confuse the categories MFA can draw from (knowledge, possession, inherence) with the number of factors Azure AD MFA actually requires; the service asks for a second factor, not a third or fourth. In Microsoft's stack, demanding an extra factor on top of MFA is step-up authentication driven by Conditional Access risk policies, not the baseline MFA definition this question targets.Community Comment Notes
All four learners converge on two factors, with no dissent. MSMN91 states "Correct Answer 2 factors are required", LegendaryZA writes "Answer: 2", and both 65daedd and Richard1985 add short confirmations like "correct" and "correcto." That unanimous agreement lines up with the SC-900 objective on authentication concepts, so the community reinforces rather than contradicts option B.Official Reference
Exam Strategy
Anchor on the definition before reading the options: MFA means two or more factors from different categories, and Azure AD MFA supplies a second factor after the password. Unless the stem explicitly describes step-up or additional verification for a high-risk sign-in, choose 2.
Frequently Asked Questions
Why do some learners answer 3 factors for Azure AD MFA?
Because MFA is often described using three factor categories (know, have, are). Azure AD MFA still enforces only two factors at sign-in, so 3 is not the required count.
Does Azure AD MFA ever require more than two factors?
Not as the baseline definition. Extra verification comes from step-up or Conditional Access risk policies, which are separate from the standard two-factor MFA requirement.
Related Analysis
Practice All SC-900 Questions
Access 141 questions with complete answers and detailed explanations.
View Full SC-900 Practice Test →