Microsoft Simplifies MFA for Windows Hello and macOS Users
Microsoft is making changes to its Entra ID service that will simplify multi-factor authentication (MFA) for users of Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO). Currently, these methods can satisfy MFA requirements during primary sign-in, but once the rollout lands, they will also be exempt from registering an additional passkey.
The change is designed to help organizations expand their use of phishing-resistant authentication methods and reduce reliance on weaker ones. WHfB and macOS PSSO credentials are bound to a device, which means users may be unable to complete an MFA challenge from another device where the credential is unavailable. Microsoft recommends that users register a portable MFA method for these situations.
No configuration changes are required for the rollout, which is expected to reach worldwide and GCC tenants starting early October 2026, with completion by late November.