MC1450134 - Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

Message Center

Summary

Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are needed, but organizations should update onboarding and documentation accordingly.

Published

Aug 7, 2026

Service

Microsoft Entra

Tag

Feature update
User impact
Admin impact

More information

What and why

Microsoft Entra will soon recognize Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO) as standalone multifactor authentication (MFA) factors in supported authentication scenarios.

Today, WHfB and macOS PSSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks.

After this rollout, users who authenticate with WHfB or macOS PSSO will be able to satisfy supported MFA requirements without registering an additional passkey. This change helps organizations expand the use of phishing-resistant authentication methods and reduce reliance on less secure authentication methods.

Rollout schedule

  • General Availability (Worldwide, GCC): Beginning in early October 2026 and expected to complete in late November 2026

Impact on your organization

Who is affected

  • Organizations using Microsoft Entra ID
  • Users who authenticate with Windows Hello for Business
  • Users who authenticate with macOS Platform SSO
  • Organizations using Conditional Access Authentication Strength policies

Platforms and services

  • Microsoft Entra ID
  • Windows Hello for Business
  • macOS Platform SSO
  • Conditional Access
  • Authentication Strength policies

What will happen

After rollout:

  • Users signing in with WHfB or macOS PSSO can complete supported MFA challenges without requiring a separate passkey.
  • WHfB and macOS PSSO will satisfy supported MFA requirements for step-up authentication scenarios.
  • WHfB and macOS PSSO can be used during 2FA to satisfy supported Authentication Strength policy requirements.
  • WHfB and macOS PSSO can be used during 2FA to satisfy supported sign-in frequency challenge requirements.
  • Users whose only MFA method is WHfB or macOS PSSO will be considered MFA-capable.
  • Users who sign in with only a password will no longer be automatically prompted to register an additional MFA method if WHfB or macOS PSSO is their only registered MFA credential.

Action required and recommendations

No configuration changes are required.

We recommend reviewing user onboarding and MFA registration processes before rollout. Because WHfB and macOS PSSO credentials are device-bound, users may not be able to complete MFA challenges from devices where those credentials are not available.

Recommended actions:

  • Update onboarding guidance to ensure users register at least one portable MFA method.
  • Consider requiring users to register a synced passkey or Microsoft Authenticator passkey in addition to WHfB or macOS PSSO.
  • Review custom Authentication Strength policies to confirm WHfB and macOS PSSO are allowed where appropriate.
  • Update user documentation because users with only WHfB or macOS PSSO registered will no longer be automatically guided to register an additional MFA method.

Learn more (To be updated closer to GA rollout.)

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.