Multi-factor Authentication Flashcards

1
Q

What are the two fraud alert options when the ‘Allow users to submit fraud alerts’ setting is turned on?

A
  • Automatically block users who report fraud
  • Code to report fraud during initial greeting
    (this code is what the user will need to enter before pressing # when reporting a fraudulent attempt)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain the “Trusted IPs” feature.

A

Trusted IPs is a feature of Azure AD Multi-Factor Authentication that allows a user to bypass multi-factor authentication prompts when signing in from a defined IP address range.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

True or False:
Trusted IPs can include private IP ranges when using cloud-based Azure AD Multi-Factor Authentication.

A

False
Trusted IPs can include private IP ranges only when you use MFA
Server. When using cloud-based Azure AD Multi-Factor Authentication, you can only use public IP
address ranges.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain the “Call to phone” verification method.

A

Places an automated voice call. The user answers the call and presses # in the
phone keypad to authenticate. The phone number is not synchronized to on-premises Active
Directory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Explain the “Text message to phone” verification method.

A

Sends a text message that contains a verification code. The user is
prompted to enter the verification code into the sign-in interface. This process is called one-way
SMS. Two-way SMS means that the user must text back a particular code. Two-way SMS is
deprecated and not supported after November 14, 2018. Administrators should enable another
method for users who previously used two-way SMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain the “notification through mobile app” verification method.

A

Sends a push notification to your phone or registered device.
The user views the notification and selects Verify to complete verification. The Microsoft
Authenticator app is available for Windows Phone, Android, and iOS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Explain the “Verification code from mobile app or hardware token” verification method.

A

The Microsoft Authenticator app
generates a new OAUTH verification code every 30 seconds. The user enters the verification code
into the sign-in interface. The Microsoft Authenticator app is available for Windows Phone,
Android, and iOS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Microsoft’s manual say about manually enforcing MFA through the multi-factor authentication admin page?

A

Do not select ‘enforce’. The user will automatically be switched to enforce when they set up their MFA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Fraud Alert used for?

A

Allows users to report fraud if they receive a two-step verification request that they didn’t initiate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is One-Time Bypass?

A

A feature that allows a user to authenticate one time without performing a 2-step verification for a limited time. This only works for MFA server (On-prem).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False:
A user can choose when they want to use One-Time Bypass without administrator intervention.

A

False
An administrator must navigate to Multi-factor Authentication > Manage MFA Server > One-time bypass > + Add, then select the user that this setting will apply to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly