The AZ-500 exam has been retired

It was retired on August 31, 2026. It was replaced by SC-500 (Microsoft Cloud and AI Security Engineer). Go to the SC-500 study guide

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.2.3. Multi-Factor Authentication (MFA)

💡 First Principle: MFA requires multiple forms of identity verification, dramatically reducing the risk of compromised credentials. Even if a password is stolen, the attacker lacks the second factor.

Scenario: All users have smartphones. You need to implement MFA without additional hardware costs.

MFA Methods and Costs

MethodRequirementsAdditional Cost
Microsoft Authenticator appSmartphoneNone
SMS verificationPhone with SMSNone
Voice call verificationPhoneNone
OATH software tokensThird-party appThird-party license
OATH hardware tokensPhysical tokenToken purchase
FIDO2 security keysHardware keyKey purchase
Windows Hello for BusinessWindows deviceNone (Windows only)

⚠️ Exam Trap: Thinking all MFA methods are equal in security. SMS is vulnerable to SIM-swapping attacks. For high-security scenarios, use phishing-resistant methods like FIDO2 keys or Windows Hello for Business.

Implementing MFA

  • Per-User MFA: Legacy method, enabled per user
  • Conditional Access MFA: Recommended, policy-based approach
  • Security Defaults: Free, basic MFA for all users (good starting point)
See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder20 professional certifications