M365 Change Tracker

← All changes · feature

In development

Microsoft Entra: Windows Hello for Business and macOS Platform Single Sign-on can now be used as a second factor for MFA

Why it matters: Breaking change — admin action may be required

From Microsoft's description: “What you need to know: Users who have only WHfB or macOS PSSO are now treated as MFA-capable and will no longer be automatically prompted to register another method.”

Windows Hello for Business (WHfB) and macOS Platform SSO (macOS PSSO) can now satisfy multifactor authentication as a standalone second factor. Previously, these methods only counted as MFA during primary sign-in, and users needed a separate passkey to complete step-up prompts, Authentication Strength policies, and sign-in frequency checks. With this change, WHfB and macOS PSSO work on their own for those scenarios, so more of your users can rely on strong, phishing-resistant sign-in without registering an extra method. What you need to know: Users who have only WHfB or macOS PSSO are now treated as MFA-capable and will no longer be automatically prompted to register another method. Because WHfB and macOS PSSO are tied to a specific device, we recommend having users register a portable method, such as a passkey or Microsoft Authenticator, during onboarding so they can complete MFA from any device.

How this was classified (derived by the tracker — not Microsoft's label)
  • Possible breaking · 55% confidence · matched breaking-cue
    What you need to know: Users who have only WHfB or macOS PSSO are now treated as MFA-capable and will no longer be automatically prompted to register another method.
Target October CY2026Cloud Worldwide, GCCPlatform Desktop, MacSource last updated 2026-08-11

Affected: Microsoft Entra

Related changes

View at Microsoft →