Source: Help Net Security
Author: Sinisa Markovic
URL: https://www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/
https://www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/
ONE SENTENCE SUMMARY:
Microsoft will let Windows Hello for Business and macOS PSSO fully satisfy Entra ID MFA, reducing extra registrations worldwide October–November 2026.
MAIN POINTS:
- Entra ID MFA behavior changes for Windows Hello for Business and macOS Platform SSO.
- Rollout targets worldwide and GCC tenants starting early October 2026.
- Deployment completion is expected by late November 2026.
- Update aims to expand phishing-resistant authentication and reduce weaker method dependence.
- Change is tracked as MC1450134 in the Microsoft 365 Message Center Archive.
- Today, step-up prompts can require registering an additional authentication method.
- After rollout, WHfB and macOS PSSO satisfy step-up MFA without extra passkey registration.
- Users with only WHfB or macOS PSSO will be treated as MFA-capable.
- Password users won’t be prompted to add MFA if WHfB or macOS PSSO is registered.
- Device-bound credentials may fail for MFA challenges initiated from other devices.
TAKEAWAYS:
- Plan for reduced MFA registration friction when WHfB/PSSO is already deployed.
- Encourage a portable backup factor, like synced passkeys or Authenticator-stored passkeys.
- Validate cross-device access scenarios where device-bound credentials cannot be used.
- Reassess Authentication Strength and sign-in frequency policies ahead of October 2026.
- Expect no admin configuration changes, but update onboarding and user guidance.