Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration
Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026. If your organization has Conditional Access policies scoped to Register security information, those policies will now apply when users set up Windows Hello for Business (WHfB) or register macOS Platform SSO credentials. Today, these registration flows enforce MFA, but do not evaluate your registration-targeting Conditional Access policies — meaning requirements like authentication strength, trusted locations, or other CA conditions aren’t enforced when users enroll WHfB or macOS Platform SSO credentials. This change closes that gap. Organizations without these policies aren’t affected. When this will happen • July 6, 2026: Gradual rollout begins. • July 13, 2026: Rollout complete for all tenants. How this affects your organization Users registering WHfB or macOS PSSO credentials will need to satisfy your registration-targeting Conditional Access policy requirements before completing enrollment. For example, a user might need to use an existing FIDO2 security key, approve a push notification in Microsoft Authenticator, or connect from a trusted network location — depending on what your policies require. Any Grant controls you’ve configured will apply. Users who don’t meet the requirements will be blocked from completing registration until the conditions are met. Action recommended In Entra admin center > Protection > Conditional Access, find policies targeting Register security information. Review Grant controls — check what requirements users must satisfy during registration (authentication strength, trusted locations, MFA method). Consider whether users setting up a new device can meet your policy requirements — for example, make sure users have a FIDO2 security key or other qualifying credential available before they start device setup. Test with report-only mode before enforcement reaches your tenant. Update helpdesk docs — users may see a new authentication prompt during device setup. If you experience issues during the rollout window (July 6–July 13), contact Microsoft Support or your account team for assistance. Learn more: Require MFA for […]
The post Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Private tasks now stored in your private plan in Planner
Starting November 2026, private tasks in Microsoft Planner will be stored in users’ private Planner plans instead of Microsoft To Do, en...
Microsoft Teams: Breakout room support for Teams Rooms on Android
Microsoft Teams Rooms on Android will support breakout rooms, allowing meeting organizers to assign and move these devices between breakout an...
Updated My Task experience in Planner
Microsoft Planner’s My Tasks experience will be redesigned for clearer navigation, better task organization, and streamlined task creati...
Microsoft Word for Android: Agent Mode
Microsoft Word for Android will gain Copilot Agent Mode by late September 2026, enabling users to draft, reason, and refine content with AI as...
Microsoft Dataverse – Bulk generate prompt column values for existing records (backfill)
We are introducing bulk generation of prompt column values for existing Dataverse records. Now, you can have AI-generated values across existi...
Microsoft Outlook: Update to default blocked file types in OwaMailboxPolicy
Outlook on the web and new Outlook for Windows will block .msix and .msixbundle file types by default in OwaMailboxPolicy starting November 20...
Dynamics 365 Contact Center: Quality evaluation – Recurring conversation evaluations
Quality Evaluation now supports recurring frequency for conversation evaluations. Previously, only event-based trigger evaluations were suppor...
Dynamics 365 Commerce: Add multiple items to a transaction using bulk entry
Associates can trigger the Bulk add operation from the button grid on the transaction screen in Store Commerce. A drawer-based dialog opens wh...
SharePoint: Advanced Management – Inactive files policy
SharePoint administrators can use the Inactive files policy in SharePoint Advanced Management to automatically archive files based on when the...
OneDrive: Presentation mode for PDFs in the iOS app on iPad
Microsoft OneDrive is introducing presentation mode in the OneDrive iOS app for users on iPad devices. Users select a new Presentation button ...