Secure Multi-Factor Authentication Methods for Remote Users

Using Multi-Factor Authentication for Remote Work

Question

You have a Microsoft 365 tenant.

All users have mobile phones and laptops.

The users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity.

While working from the remote locations, the users connect their laptop to a wired network that has internet access.

You plan to implement multi-factor authentication (MFA)

Which MFA authentication method can the users use from the remote location?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

C.

An automated voice call is made to the phone number registered by the user.

To complete the sign-in process, the user is prompted to press # on their keypad.

Incorrect Answers: A: The Microsoft Authenticator app requires a mobile phone that runs Android or iOS B: Security questions are not used as an authentication method but can be used during the self-service password reset (SSPR) process.

D: SMS requires a mobile phone - Reference: https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-methods.

In the given scenario, users frequently work from remote locations that do not have Wi-Fi access or mobile phone connectivity. While working from these locations, the users connect their laptops to a wired network that has internet access. To implement multi-factor authentication (MFA), the users need to have access to an MFA authentication method that works without mobile phone connectivity or Wi-Fi access.

Out of the given options, the authentication method that can be used by the users from the remote location is A. a verification code from the Microsoft Authenticator app.

The Microsoft Authenticator app generates verification codes that can be used as a second factor for authentication. The app works offline, which means that even if the user does not have internet access or mobile phone connectivity, they can still generate verification codes. The app works by generating a time-based one-time password (TOTP), which means that the verification code changes after a certain period (usually 30 seconds).

To use the Microsoft Authenticator app, the user needs to set it up on their mobile phone before going to the remote location. During the setup process, the user links their Microsoft account to the app. Once the app is set up, the user can generate verification codes by launching the app and tapping on the account linked to their Microsoft account.

In conclusion, the users can use the Microsoft Authenticator app to generate verification codes as an MFA authentication method from the remote location. The app works offline, which means that the users can still generate verification codes even if they do not have internet access or mobile phone connectivity.