Global Administrators must use phishing-resistant authentication with FIDO2 security keys. What must the admin enable/configure?
Select an answer to reveal the explanation.
Short Explanation and Infographic
FIDO2 keys are the 'can't phish me with a fake login page' method. Enable methods, then force with CA strengths.
Full explanation below image
Full Explanation
Correct Answer — B
Enable FIDO2 in authentication methods and enforce phishing-resistant authentication strengths with CA for privileged roles. SMS is not phishing-resistant. Disabling MFA or password-only fails the goal.
Exam tip: Phishing-resistant admin auth → FIDO2 + CA authentication strength.