SHD / MC Checker

MC1450134 | Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors



MC1450134 | Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

Classification planForChange
Last Updated 08/07/2026 21:56:16
Start Time 08/07/2026 21:56:10
End Time 12/20/2026 08:00:00
Message Content

[What and why]

Microsoft Entra will soon recognize Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO) as standalone multifactor authentication (MFA) factors in supported authentication scenarios.

Today, WHfB and macOS PSSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks.

After this rollout, users who authenticate with WHfB or macOS PSSO will be able to satisfy supported MFA requirements without registering an additional passkey. This change helps organizations expand the use of phishing-resistant authentication methods and reduce reliance on less secure authentication methods.

[Rollout schedule]

  • General Availability (Worldwide, GCC): Beginning in early October 2026 and expected to complete in late November 2026

[Impact on your organization]

Who is affected

  • Organizations using Microsoft Entra ID
  • Users who authenticate with Windows Hello for Business
  • Users who authenticate with macOS Platform SSO
  • Organizations using Conditional Access Authentication Strength policies

Platforms and services

  • Microsoft Entra ID
  • Windows Hello for Business
  • macOS Platform SSO
  • Conditional Access
  • Authentication Strength policies

What will happen

After rollout:

  • Users signing in with WHfB or macOS PSSO can complete supported MFA challenges without requiring a separate passkey.
  • WHfB and macOS PSSO will satisfy supported MFA requirements for step-up authentication scenarios.
  • WHfB and macOS PSSO can be used during 2FA to satisfy supported Authentication Strength policy requirements.
  • WHfB and macOS PSSO can be used during 2FA to satisfy supported sign-in frequency challenge requirements.
  • Users whose only MFA method is WHfB or macOS PSSO will be considered MFA-capable.
  • Users who sign in with only a password will no longer be automatically prompted to register an additional MFA method if WHfB or macOS PSSO is their only registered MFA credential.

[Action required and recommendations]

No configuration changes are required.

We recommend reviewing user onboarding and MFA registration processes before rollout. Because WHfB and macOS PSSO credentials are device-bound, users may not be able to complete MFA challenges from devices where those credentials are not available.

Recommended actions:

  • Update onboarding guidance to ensure users register at least one portable MFA method.
  • Consider requiring users to register a synced passkey or Microsoft Authenticator passkey in addition to WHfB or macOS PSSO.
  • Review custom Authentication Strength policies to confirm WHfB and macOS PSSO are allowed where appropriate.
  • Update user documentation because users with only WHfB or macOS PSSO registered will no longer be automatically guided to register an additional MFA method.

Learn more (To be updated closer to GA rollout.)

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Machine Translation

[何となぜ]

Microsoft Entraはまもなく、Windows Hello for Business(WHfB)およびmacOSプラットフォーム・シングルサインオン(PSSO)を、サポートされている認証シナリオにおいてスタンドアロンの多要素認証(MFA)ファクターとして認識する予定です。

現在、WHfBおよびmacOS PSSOはプライマリサインイン時にMFA要件を満たすことができますが、特定のステップアップ認証プロンプト、認証強度ポリシー、サインイン頻度チェックのために追加のパスキーや認証方法の登録や使用が求められる場合があります。

この展開後、WHfBまたはmacOS PSSOで認証するユーザーは、追加のパスキー登録なしでサポートされたMFA要件を満たすことができます。この変更により、組織はフィッシング耐性認証方法の利用を拡大し、安全性の低い認証方法への依存を減らすことができます。

[展開スケジュール]

  • 一般公開(世界、GCC):2026年10月初旬に 開始、2026年11月下旬に完了予定です

[組織への影響]

影響を受ける人物

  • Microsoft Entra IDを利用する組織
  • Windows Hello for Businessで認証するユーザー
  • macOSプラットフォームSSOで認証するユーザー
  • 条件付きアクセス認証強度ポリシーを使用する組織

ホームとサービス

  • Microsoft Entra ID
  • Windows Hello for Business(ビジネス用 Windows Hello)
  • macOS Platform SSO
  • 条件付きアクセス
  • 認証強度ポリシー

何が起こるのか

展開後:

  • WHfBまたはmacOS PSSOでサインインするユーザーは、別のパスキーなしで対応可能なMFAチャレンジを完了できます。
  • WHfBおよびmacOS PSSOは、ステップアップ認証シナリオでサポートされているMFA要件を満たします。
  • WHfBおよびmacOS PSSOは、2FA中に使用され、サポートされる認証強度ポリシー要件を満たすことができます。
  • WHfBおよびmacOS PSSOは、2FA中に使用され、対応されるサインイン周波数チャレンジの要件を満たすことができます。
  • WHfBまたはmacOS PSSOのみのMFA方法を持つユーザーはMFA対応と見なされます。
  • パスワードのみでサインインしたユーザーは、WHfBまたはmacOS PSSOのみが登録済みMFA認証情報であれば、追加のMFA方法登録を自動的に促されることはなくなります。

[行動が必要と提言]

設定の変更は一切必要ありません。

導入前にユーザーのオンボーディングおよびMFA登録プロセスを確認することをお勧めします。WHfBおよびmacOSのPSSO認証情報はデバイスにバインドされているため、認証情報が利用できないデバイスからはMFAチャレンジを完了できない場合があります。

推奨される行動:

  • ユーザーが少なくとも1つのポータブルMFAメソッドを登録できるようにオンボーディングガイダンスを更新してください。
  • WHfBやmacOS PSSOに加えて、同期パスキーやMicrosoft Authenticatorパスキーの登録をユーザーに求めることを検討してください。
  • カスタム認証強度ポリシーを確認し、適切な場合にWHfBおよびmacOS PSSOが許可されているか確認してください。
  • ユーザードキュメントの更新は、WHfBまたはmacOS PSSOのみ登録のユーザーは追加のMFA方法登録を自動で案内されなくなるためです。

詳細 はこちら(GA導入が近づくにつれて更新されます)

[コンプライアンスの考慮事項]

コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。