certslothcertsloth
SC-300/Topic 03

Microsoft / Associate

Authentication Methods, Recovery and Passwordless Access

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Strong proof matters at enrollment, sign-in and recovery.

Must remember

Plan authentication methods around phishing resistance, user population, device support and recovery. Passkeys/FIDO2, certificate-based authentication, Microsoft Authenticator and Windows Hello for Business provide different supported experiences and assurance. MFA means independent factors, not two passwords. Protect method registration because an attacker who enrolls a factor may persist after a password change.

A Temporary Access Pass supports controlled bootstrap/recovery for supported passwordless methods. Limit its lifetime/use and verify the recipient. SSPR enables eligible users to reset passwords after configured verification; hybrid writeback requires the supported configuration. Authentication-method policy, registration campaigns and Conditional Access work together but have different purposes.

Password Protection blocks weak/banned patterns under supported cloud/on-premises deployment. Windows Hello for Business binds supported key-based credentials to device/user gestures; do not confuse it with a reusable password shared across devices. Entra Kerberos supports particular hybrid identity/resource scenarios with prerequisites and trust configuration.

When an account is compromised, disable/restrict it as appropriate, revoke sessions and investigate persistence, methods and app consent. Token/session revocation behavior differs across resources; it is not proof that every offline or application-local session instantly disappears. Keep monitored emergency access independent of common failure paths.

Choose under exam pressure

Requirement Choice and reason
Bootstrap a passwordless method Controlled Temporary Access Pass where supported.
Reduce phishing exposure Appropriate phishing-resistant methods and policy.
Hybrid self-service password reset SSPR with required writeback and verification configuration.

Traps

  • Two knowledge secrets are not two independent factors.
  • Resetting a password alone may leave malicious authentication methods or app consent.

Active recall

1. Why secure registration?

It establishes future proof-of-identity methods.

2. What is a TAP for?

Time-limited bootstrap/recovery for supported authentication setup.

3. Does MFA mean every method resists phishing equally?

No; method properties differ.

4. Why verify session behavior after revocation?

Resources and token types can handle revocation differently.

5. Why keep emergency access?

To recover when normal federation, policy or authentication dependencies fail.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.