Loading...

Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are needed, but organizations should update onboarding and documentation accordingly. Microsoft Entra will soon recognize Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO) as standalone multifactor authentication (MFA) factors in supported authentication scenarios. Today, WHfB and macOS PSSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks. After this rollout, users who authenticate with WHfB or macOS PSSO will be able to satisfy supported MFA requirements without registering an additional passkey. This change helps organizations expand the use of phishing-resistant authentication methods and reduce reliance on less secure authentication methods. Rollout schedule General Availability (Worldwide, GCC): Beginning in early October 2026 and expected to complete in late November 2026 Impact on your organization Who is affected Organizations using Microsoft Entra ID Users who authenticate with Windows Hello for Business Users who authenticate with macOS Platform SSO Organizations using Conditional Access Authentication Strength policies Platforms and services Microsoft Entra ID Windows Hello for Business macOS Platform SSO Conditional Access Authentication Strength policies What will happen After rollout: Users signing in with WHfB or macOS PSSO can complete supported MFA challenges without requiring a separate passkey. WHfB and macOS PSSO will satisfy supported MFA requirements for step-up authentication scenarios. WHfB and macOS PSSO can be used during 2FA to satisfy supported Authentication Strength policy requirements. WHfB and macOS PSSO can be used during 2FA to satisfy supported sign-in frequency challenge requirements. Users whose only MFA method is WHfB or macOS PSSO will be considered MFA-capable. Users who sign in with only a password will no longer be automatically prompted to register an additional MFA method if WHfB or macOS PSSO is their only registered MFA credential. Action required and recommendations No configuration changes are required. We recommend reviewing user onboarding and MFA registration […]

The post Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams

Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...

3 days ago

Microsoft Teams: Enable agents for existing applications in your organization

For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...

3 days ago

Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile

The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...

4 days ago

Planner: Conditional Coloring

Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...

4 days ago

Outlook: Offline settings “Days of email to save” admin policy

Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...

4 days ago

Microsoft Copilot Studio: Agent Sharing amongst makers

Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...

4 days ago

OneDrive Photos on Windows: admin controls and policy support

OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...

4 days ago

Admin app retiring in Teams, Outlook and Microsoft365.com

The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...

4 days ago

Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting

Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...

4 days ago

Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices

The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...

4 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.