Authentication Fundamentals
Authentication Fundamentals
Authentication is the process of verifying that an identity is who or what it claims to be.
In Microsoft Entra environments, authentication is much more than entering a username and password. Organizations can use multifactor authentication, passwordless methods, self-service capabilities, and authentication policies to strengthen access while balancing security and usability.
Understanding these concepts provides an important foundation for SC-300 and prepares you for Conditional Access in the next lesson.
What You’ll Learn
By the end of this lesson, you should be able to:
- Explain the difference between authentication and authorization
- Understand authentication factors
- Explain the purpose of multifactor authentication
- Recognize common passwordless authentication approaches
- Understand the purpose of Self-Service Password Reset
- Recognize why stronger authentication matters
- Understand how authentication fits into a broader access strategy
Authentication vs. Authorization
Before going further, remember the distinction introduced earlier in this course.
Authentication verifies identity.
Authorization determines what an authenticated identity is permitted to access.
Consider an employee attempting to open an HR application.
First, the organization needs to establish:
“Is this really the employee?”
That is authentication.
After the identity is verified, the organization determines:
“Is this employee permitted to access this application?”
That is authorization.
Successful authentication does not automatically mean a user should have access to every resource.
Authentication Factors
Authentication can rely on different types of evidence, commonly called authentication factors.
Three familiar categories are:
Something You Know
Information known by the user.
Examples include:
- Passwords
- PINs
Something You Have
An item or device possessed by the user.
Examples can include:
- A security key
- A registered authentication device
- Certain hardware-based credentials
Something You Are
A characteristic of the person, generally involving biometrics.
Examples include:
- Fingerprint recognition
- Facial recognition
Understanding these categories is important because they help explain the purpose of multifactor authentication.
Multifactor Authentication
Multifactor authentication (MFA) requires evidence from more than one authentication factor.
For example, consider a sign-in requiring:
Password + approved second authentication factor
The password represents something the user knows, while the additional method can provide evidence from another factor.
The security advantage is straightforward.
If an attacker obtains only the user’s password, that credential alone may no longer be sufficient to complete authentication.
This makes MFA an important defense against many credential-based attacks.
Why Passwords Alone Can Be Risky
Passwords remain common, but they can be exposed in several ways.
Examples include:
- Phishing
- Credential theft
- Password reuse
- Weak passwords
- Data breaches
- Social engineering
A user may choose a strong password and still be tricked into providing it to an attacker.
For this reason, modern identity security increasingly relies on controls that reduce dependence on passwords alone.
Passwordless Authentication
Passwordless authentication allows users to authenticate without relying on a traditional password as the primary sign-in secret.
Depending on the environment and configuration, Microsoft identity solutions can support passwordless approaches such as:
- Windows Hello for Business
- FIDO2 security keys
- Supported Microsoft Authenticator passwordless experiences
The important concept is not simply convenience.
Reducing dependence on reusable passwords can also reduce exposure to certain password-related attacks.
Different authentication methods provide different security properties, so organizations should choose methods according to their requirements and supported environments.
Authentication Methods
Organizations need to consider which authentication methods users are permitted or expected to use.
Different populations may have different requirements.
For example:
- Standard employees may use approved authentication methods for everyday access.
- Administrators may require stronger authentication controls.
- Certain users may require passwordless authentication.
- Temporary onboarding or recovery scenarios may require specialized methods.
Authentication therefore needs to be managed as part of an organization’s overall identity strategy rather than treated as a single universal login configuration.
Self-Service Password Reset
Self-Service Password Reset (SSPR) can allow eligible users to reset or change their passwords without requiring the help desk to perform every password-reset operation.
This can benefit both users and IT teams.
Users can recover access more efficiently, while support teams can spend less time performing routine password-reset work.
However, password reset is a security-sensitive process.
Before allowing a password to be reset, the system needs sufficient assurance that the person requesting the reset is actually the legitimate user.
This is why authentication methods and registration are important components of account recovery.
Combined Registration
Organizations may provide users with a more unified experience for registering information used by authentication and self-service password reset capabilities.
From the learner’s perspective, the important concept is that authentication-method registration should be managed carefully.
If users have not registered appropriate methods, security and account-recovery processes may become more difficult.
Practical Scenario: Stolen Password
Suppose an attacker successfully obtains Jordan’s corporate password through a phishing campaign.
If Jordan’s account relies only on that password, the attacker may have enough information to attempt authentication.
Now suppose the organization requires an additional approved authentication factor.
The stolen password by itself may no longer be sufficient.
This illustrates an important security principle:
A compromised password should not necessarily equal a compromised account.
Strong authentication helps organizations reduce the risk created by stolen credentials.
Practical Scenario: Help Desk Password Reset
Suppose Taylor forgets a corporate password on Sunday evening.
Without self-service capabilities, Taylor may need to wait for the help desk before regaining access.
With properly configured SSPR, an eligible user may be able to complete the required verification process and reset the password without direct help-desk intervention.
The organization gains convenience, but the verification process must still protect against unauthorized resets.
Security and usability both matter.
Authentication Is Only Part of the Decision
Strong authentication is extremely important, but authentication alone does not answer every access question.
Imagine two successful sign-ins:
Sign-in A: An employee uses an expected device under normal circumstances.
Sign-in B: The same employee attempts to access a sensitive resource under circumstances that trigger additional organizational access requirements.
The identity may successfully authenticate in both cases, but the organization may not want to treat both access attempts identically.
This leads to a broader question:
Under what conditions should access be allowed, blocked, or require additional controls?
That is where Conditional Access becomes important.
SC-300 Exam Focus
When working through authentication scenarios, identify exactly what the question is trying to accomplish.
If the requirement is to reduce reliance on passwords, consider passwordless authentication.
If the requirement is to require more than one authentication factor, think MFA.
If users need to recover or reset their passwords without routine help-desk intervention, think SSPR.
Also remember that:
Authentication methods establish identity assurance.
They do not automatically determine every authorization or access decision.
Avoid treating authentication, authorization, and Conditional Access as interchangeable concepts.
Quick Review
Before continuing, make sure you understand:
- Authentication verifies identity.
- Authorization determines permitted access.
- Authentication factors include something you know, have, or are.
- MFA uses more than one authentication factor.
- Passwordless authentication reduces dependence on traditional passwords.
- Microsoft identity environments can support multiple authentication methods.
- SSPR can allow eligible users to perform password recovery or reset without routine help-desk assistance.
- Authentication-method registration is an important part of identity security.
- Strong authentication is one component of a broader access strategy.
Continue to Lesson 5
You now understand the foundations of identities and authentication.
Next, we’ll move beyond simply verifying a user and examine how organizations can make access decisions based on conditions, signals, and risk.
Next: Conditional Access and Identity Protection →