Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

🚨 The Signal: Windows Hello for Business and macOS Platform SSO will now satisfy all Microsoft Entra MFA requirements as standalone factors. This enhances phishing-resistant authentication and reduces reliance on less secure methods.

The Impact

Organizations using Microsoft Entra ID and Conditional Access Authentication Strengths are affected, reducing reliance on less secure MFA methods.

  • Security Teams: Reduced risk from phishing attacks due to stronger MFA.
  • End Users: Smoother sign-in experience with fewer MFA prompts.
  • Admins: Potential review of Conditional Access policies for MFA requirements.
  • Organizations: Improved overall authentication security posture.

The Action

  1. Review Conditional Access Authentication Strength policies to ensure WHfB/PSSO are appropriately configured as phishing-resistant MFA.
  2. Communicate to users about the enhanced capabilities of WHfB and macOS PSSO for MFA.
  3. Monitor sign-in logs for successful MFA challenges using WHfB and PSSO.

Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907