Authentication methods

Authentication is the process of proving a user's identity, using methods such as passwords, the Microsoft Authenticator app, FIDO2 security keys, Windows Hello, and passkeys.

Microsoft Entra ID supports a range of authentication methods — passwords, the Microsoft Authenticator app, FIDO2 security keys, Windows Hello for Business, certificate-based authentication, and passkeys — that administrators control through the Authentication methods policy in the Entra admin center, enabling or disabling each method per user group. A key exam distinction is that Microsoft is consolidating method management into this policy and retiring the legacy per-user MFA settings. Phishing-resistant methods such as FIDO2, passkeys, and Windows Hello for Business resist adversary-in-the-middle attacks, making them preferred for privileged accounts and Conditional Access requirements.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Core Microsoft 365 Services & Identity