Valid SC-300 Dumps shared by EduDump.com for Helping Passing SC-300 Exam! EduDump.com now offer the newest SC-300 exam dumps, the EduDump.com SC-300 exam questions have been updated and answers have been corrected get the newest EduDump.com SC-300 dumps with Test Engine here:
You have an Azure AD tenant that has multi-factor authentication (MFA) enforced and self-service password reset (SSPR) enabled. You enable combined registration in interrupt mode. You create a new user named User1. Which two authentication methods can User1 use to complete the combined registration process? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
Correct Answer: C,E
To Answer this question accurately, we must analyze the Combined Security Information Registration experience in Interrupt Mode for a new user within an Azure AD (Microsoft Entra ID) tenant where both MFA and SSPR are enabled. 1. Understanding Combined Registration in Interrupt Mode: According to Microsoft documentation on Combined security information registration, this feature allows users to register their security methods for both Azure AD Multi-Factor Authentication (MFA) and Self-Service Password Reset (SSPR) in a single, unified step. * Interrupt Mode triggers when a user signs in and a policy (like Identity Protection or Conditional Access) requires them to register security information immediately. * Because the question states SSPR is enabled and MFA is enforced, the user is required to register methods that satisfy both policies. 2. Validating the Methods (Options Analysis): * Option E: The Microsoft Authenticator app (Correct): The Microsoft Authenticator app is the primary and most recommended method in the combined registration flow. It satisfies the strong authentication requirement for MFA and can also be used for SSPR. Microsoft documentation explicitly lists the Microsoft Authenticator app as a supported method that users can register during the combined experience. * Option C: A one-time passcode email (Correct): While Email is not a valid method for Azure AD MFA (primary authentication), it is a supported and common method for SSPR. * Documentation Extract: "Users can register the following methods... Email (SSPR only)." * Since the question specifies that SSPR is enabled, the combined registration wizard requires the user to register SSPR methods in addition to MFA methods. Therefore, registering an email address to receive a one-time passcode is a valid step User1 can take to complete the portion of the combined registration process related to SSPR. * Option A: A FIDO2 security key (Incorrect for Initial Registration): * Documentation Extract: "User registration of FIDO2 security keys... relies on the combined registration experience. Users must have already registered at least one Azure AD Multi- Factor Authentication method." * Because User1 is a new user (and likely does not have a Temporary Access Pass specified), they cannot use a FIDO2 key to complete the initial registration interrupt. They must first register a standard MFA method (like the Authenticator app) before they can add a FIDO2 key via the "Manage" mode (Security Info page). * Option B: A hardware token (Incorrect): Hardware OATH tokens are not self-registered by the user in the combined registration portal. They must be uploaded and assigned by an administrator via a CSV file. Therefore, User1 cannot "use" this method to complete the self-service registration process. * Option D: Windows Hello for Business (Incorrect): Windows Hello for Business (WHfB) is provisioned at the device level (via Windows Settings or OOBE), not through the web-based Combined Registration interrupt wizard. Additionally, WHfB typically requires the user to have already completed MFA registration to provision the credential. Conclusion: The only two methods from the list that a new user can actively register and use to complete the web-based Combined Registration interrupt wizard (satisfying both MFA and SSPR requirements) are the Microsoft Authenticator app (for MFA/SSPR) and Email (for SSPR).