Microsoft 365 Administrator Expert MS-102 Practice Question
Your organization wants to roll out passwordless sign-in by using FIDO2 security keys. The security team stipulates that only YubiKey 5 NFC devices (AAGUID fa2b99dc-9e38-4b94-8a36-f6e2773c17e3) can be registered and that Microsoft Entra ID must validate the device manufacturer during key registration. You create an authentication methods policy and enable the FIDO2 security key method. Which configuration change meets both security requirements?
Set User verification requirement to Discouraged and add the AAGUID to a deny list in the policy.
Require registration from hybrid Azure AD-joined devices only and add the AAGUID under Allowed tenants.
Disable Enforce attestation and, under Enforce key restrictions, choose Block and enter the approved AAGUID.
Set Enforce attestation to Yes and, under Enforce key restrictions, choose Allow and enter the approved AAGUID.
To accept only a specific FIDO2 model, you must use key attestation so that Microsoft Entra ID can read the authenticator's AAGUID. In the FIDO2 authentication methods policy you therefore set Enforce attestation to Yes and, under Enforce key restrictions, choose Allow and enter the approved AAGUID list. Disabling attestation, adding the AAGUID to a deny list, or restricting device join types would not simultaneously validate the manufacturer and restrict registration to a single key model.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an AAGUID in relation to FIDO2 security keys?
Open an interactive chat with Bash
How does Enforce Attestation enhance security during FIDO2 key registration?
Open an interactive chat with Bash
What are the benefits of using FIDO2 security keys for passwordless sign-in?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Implement and manage Microsoft Entra identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .