| MC1450134 | Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors |
|---|
| Classification | planForChange |
|---|---|
| Last Updated | 08/07/2026 21:56:16 |
| Start Time | 08/07/2026 21:56:10 |
| End Time | 12/20/2026 08:00:00 |
| Message Content |
[What and why] Microsoft Entra will soon recognize Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO) as standalone multifactor authentication (MFA) factors in supported authentication scenarios. Today, WHfB and macOS PSSO can satisfy MFA requirements during primary sign-in, but users may still be required to register and use an additional passkey or authentication method for certain step-up authentication prompts, Authentication Strength policies, and sign-in frequency checks. After this rollout, users who authenticate with WHfB or macOS PSSO will be able to satisfy supported MFA requirements without registering an additional passkey. This change helps organizations expand the use of phishing-resistant authentication methods and reduce reliance on less secure authentication methods. [Rollout schedule]
[Impact on your organization] Who is affected
Platforms and services
What will happen After rollout:
[Action required and recommendations] No configuration changes are required. We recommend reviewing user onboarding and MFA registration processes before rollout. Because WHfB and macOS PSSO credentials are device-bound, users may not be able to complete MFA challenges from devices where those credentials are not available. Recommended actions:
Learn more (To be updated closer to GA rollout.)
[Compliance considerations] No compliance considerations identified. Review as appropriate for your organization. |
| Machine Translation |
[何となぜ] Microsoft Entraはまもなく、Windows Hello for Business(WHfB)およびmacOSプラットフォーム・シングルサインオン(PSSO)を、サポートされている認証シナリオにおいてスタンドアロンの多要素認証(MFA)ファクターとして認識する予定です。 現在、WHfBおよびmacOS PSSOはプライマリサインイン時にMFA要件を満たすことができますが、特定のステップアップ認証プロンプト、認証強度ポリシー、サインイン頻度チェックのために追加のパスキーや認証方法の登録や使用が求められる場合があります。 この展開後、WHfBまたはmacOS PSSOで認証するユーザーは、追加のパスキー登録なしでサポートされたMFA要件を満たすことができます。この変更により、組織はフィッシング耐性認証方法の利用を拡大し、安全性の低い認証方法への依存を減らすことができます。 [展開スケジュール]
[組織への影響] 影響を受ける人物
ホームとサービス
何が起こるのか 展開後:
[行動が必要と提言] 設定の変更は一切必要ありません。 導入前にユーザーのオンボーディングおよびMFA登録プロセスを確認することをお勧めします。WHfBおよびmacOSのPSSO認証情報はデバイスにバインドされているため、認証情報が利用できないデバイスからはMFAチャレンジを完了できない場合があります。 推奨される行動:
詳細 はこちら(GA導入が近づくにつれて更新されます)
[コンプライアンスの考慮事項] コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行ってください。 |