Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Source: Help Net Security

Author: Sinisa Markovic

URL: https://www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/

https://www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/

ONE SENTENCE SUMMARY:

Microsoft will let Windows Hello for Business and macOS PSSO fully satisfy Entra ID MFA, reducing extra registrations worldwide October–November 2026.

MAIN POINTS:

  1. Entra ID MFA behavior changes for Windows Hello for Business and macOS Platform SSO.
  2. Rollout targets worldwide and GCC tenants starting early October 2026.
  3. Deployment completion is expected by late November 2026.
  4. Update aims to expand phishing-resistant authentication and reduce weaker method dependence.
  5. Change is tracked as MC1450134 in the Microsoft 365 Message Center Archive.
  6. Today, step-up prompts can require registering an additional authentication method.
  7. After rollout, WHfB and macOS PSSO satisfy step-up MFA without extra passkey registration.
  8. Users with only WHfB or macOS PSSO will be treated as MFA-capable.
  9. Password users won’t be prompted to add MFA if WHfB or macOS PSSO is registered.
  10. Device-bound credentials may fail for MFA challenges initiated from other devices.

TAKEAWAYS:

  1. Plan for reduced MFA registration friction when WHfB/PSSO is already deployed.
  2. Encourage a portable backup factor, like synced passkeys or Authenticator-stored passkeys.
  3. Validate cross-device access scenarios where device-bound credentials cannot be used.
  4. Reassess Authentication Strength and sign-in frequency policies ahead of October 2026.
  5. Expect no admin configuration changes, but update onboarding and user guidance.