Skip to Content

MC1450134 Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

Summary

Microsoft Entra will soon recognize Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO) as standalone multifactor authentication (MFA) factors in supported authentication scenarios.

Today, WHfB and macOS PSSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks.

After this rollout, users who authenticate with WHfB or macOS PSSO will be able to satisfy supported MFA requirements without registering an additional passkey. This change helps organizations expand the use of phishing-resistant authentication methods and reduce reliance on less secure authentication methods.

Microsoft 365 Message Center ID: MC1450134
Last Modified: August 8, 2026
Category: Message Center
Tags: New feature, Feature update, User impact
Status: Launched
Products & Platforms: Microsoft Entra

Rollout schedule

General Availability (Worldwide, GCC): Beginning in early October 2026 and expected to complete in late November 2026

Impact on your organization

Who is affected

  • Organizations using Microsoft Entra ID
  • Users who authenticate with Windows Hello for Business
  • Users who authenticate with macOS Platform SSO
  • Organizations using Conditional Access Authentication Strength policies

Platforms and services

  • Microsoft Entra ID
  • Windows Hello for Business
  • macOS Platform SSO
  • Conditional Access
  • Authentication Strength policies

What will happen

After rollout:

  • Users signing in with WHfB or macOS PSSO can complete supported MFA challenges without requiring a separate passkey.
  • WHfB and macOS PSSO will satisfy supported MFA requirements for step-up authentication scenarios.
  • WHfB and macOS PSSO can be used during 2FA to satisfy supported Authentication Strength policy requirements.
  • WHfB and macOS PSSO can be used during 2FA to satisfy supported sign-in frequency challenge requirements.
  • Users whose only MFA method is WHfB or macOS PSSO will be considered MFA-capable.
  • Users who sign in with only a password will no longer be automatically prompted to register an additional MFA method if WHfB or macOS PSSO is their only registered MFA credential.

Action required and recommendations

No configuration changes are required.

We recommend reviewing user onboarding and MFA registration processes before rollout. Because WHfB and macOS PSSO credentials are device-bound, users may not be able to complete MFA challenges from devices where those credentials are not available.

Recommended actions:

  • Update onboarding guidance to ensure users register at least one portable MFA method.
  • Consider requiring users to register a synced passkey or Microsoft Authenticator passkey in addition to WHfB or macOS PSSO.
  • Review custom Authentication Strength policies to confirm WHfB and macOS PSSO are allowed where appropriate.
  • Update user documentation because users with only WHfB or macOS PSSO registered will no longer be automatically guided to register an additional MFA method.

Learn more (To be updated closer to GA rollout.)

  • Plan a Windows Hello for Business deployment | Security | Windows | Microsoft Learn
  • Prepare users to provision and use Windows Hello for Business | Security | Windows | Microsoft Learn

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.