Starting inΒ October 2026, Microsoft is enhancing how Windows Hello for Business (WHfB) and macOS Platform SSO (PSSO) credentials are recognized during Microsoft Entra authentication.

Today, users who already have these strong, device-bound credentials may still encounter scenarios where they're asked to register or use another passkey for:

πŸ”Ή Step-up authentication
πŸ”Ή Authentication Strength requirements
πŸ”Ή Sign-in frequency challenges

With the upcoming change, WHfB and macOS Platform SSO can satisfy supported MFA requirements using the credential already bound to the user's device, reducing the need for an additional passkey.

πŸ›‘οΈ Why this matters

Both technologies use hardware-backed, device-bound credentials.

Windows Hello for Business ties the user's credential directly to their Windows device and protects key material using hardware such as the TPM.

macOS Platform SSO with Secure Enclave similarly uses a hardware-bound cryptographic key and can provide phishing-resistant, passwordless authentication on managed Macs.

That means organizations can potentially deliver:

βœ… Stronger authentication
βœ… Fewer unnecessary authentication prompts
βœ… Better user experience
βœ… Reduced dependence on passwords
βœ… Greater adoption of phishing-resistant authentication

⚠️ But there's an important consideration

Device-bound means device-bound.

If the user needs to authenticate from another device where their Windows Hello or macOS Platform credential isn't available, they'll need another registered authentication method. Microsoft also allows users to choose another registered method through β€œSign in another way” when available.

So while the change can reduce authentication friction, organizations should still think about credential portability and recovery.

IT teams should consider:

πŸ”Ή Reviewing authentication-method registration
πŸ”Ή Maintaining appropriate backup authentication methods
πŸ”Ή Reviewing Authentication Strength policies
πŸ”Ή Preparing users who work across multiple devices
πŸ”Ή Updating helpdesk and recovery procedures

πŸ’‘ Bottom line: The goal isn't simply fewer MFA prompts. It's to make phishing-resistant authentication the normal sign-in experience while ensuring users still have a secure way to authenticate when their primary device isn't available.

Stronger authentication + less friction + a solid recovery strategy = better identity security.

3f27a3dd-af14-4ba1-aa59-cbfc0656bd7a