Starting inΒ October 2026, Microsoft is enhancing how Windows Hello for Business (WHfB) and macOS Platform SSO (PSSO) credentials are recognized during Microsoft Entra authentication.
Today, users who already have these strong, device-bound credentials may still encounter scenarios where they're asked to register or use another passkey for:
πΉ Step-up authentication
πΉ Authentication Strength requirements
πΉ Sign-in frequency challenges
With the upcoming change, WHfB and macOS Platform SSO can satisfy supported MFA requirements using the credential already bound to the user's device, reducing the need for an additional passkey.
π‘οΈ Why this matters
Both technologies use hardware-backed, device-bound credentials.
Windows Hello for Business ties the user's credential directly to their Windows device and protects key material using hardware such as the TPM.
macOS Platform SSO with Secure Enclave similarly uses a hardware-bound cryptographic key and can provide phishing-resistant, passwordless authentication on managed Macs.
That means organizations can potentially deliver:
β
Stronger authentication
β
Fewer unnecessary authentication prompts
β
Better user experience
β
Reduced dependence on passwords
β
Greater adoption of phishing-resistant authentication
β οΈ But there's an important consideration
Device-bound means device-bound.
If the user needs to authenticate from another device where their Windows Hello or macOS Platform credential isn't available, they'll need another registered authentication method. Microsoft also allows users to choose another registered method through βSign in another wayβ when available.
So while the change can reduce authentication friction, organizations should still think about credential portability and recovery.
IT teams should consider:
πΉ Reviewing authentication-method registration
πΉ Maintaining appropriate backup authentication methods
πΉ Reviewing Authentication Strength policies
πΉ Preparing users who work across multiple devices
πΉ Updating helpdesk and recovery procedures
π‘ Bottom line: The goal isn't simply fewer MFA prompts. It's to make phishing-resistant authentication the normal sign-in experience while ensuring users still have a secure way to authenticate when their primary device isn't available.
Stronger authentication + less friction + a solid recovery strategy = better identity security.
