Planning and implementing device authentication methods
With Azure AD MFA deployed in your environment, you need to consider the available authentication methods. There are many options available and they are all listed briefly in this section. Links to more detailed information and instructions on each of these methods are included in the Further reading section at the end of this chapter.
In Azure AD, a password is still typically the primary means of authentication. However, passwordless authentication methods are available and include Windows Hello, FIDO security keys, and the Microsoft Authenticator app (all of which are described briefly in Chapter 1, Planning for Hybrid Identity). These methods provide the most secure sign-in experience for users in Microsoft 365, and Microsoft recommends replacing passwords with a passwordless method where practical and possible.
The following table presents the different authentication methods available in Azure AD and the level of security...