StudyToCert

All certifications / SC-500 / Lessons

Microsoft Certified: Cloud and AI Security Engineer Associate (replaces Azure Security Engineer Associate / AZ-500) SC-500 · Domain 1: Manage identity, access, and governance

MFA and authentication methods policy, phishing-resistant methods (FIDO2, passkeys, Windows Hello), authentication strengths

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Multifactor authentication (MFA) requires two or more of: something you know (password or PIN), something you have (phone, security key) and something you are (fingerprint, face). A stolen password alone is then not enough. In Microsoft Entra ID you can require MFA through security defaults (a free, all-or-nothing baseline) or, for finer control, through Conditional Access policies. The old per-user MFA setting is legacy and should be avoided in favor of Conditional Access.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-500 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-500 study plan