Microsoft Entra: Windows Hello for Business and macOS Platform Single Sign-on can now be used as a second factor for MFA

🚨 The Signal: Windows Hello for Business and macOS Platform SSO now fully satisfy MFA as a second factor, removing the need for an additional passkey for step-up prompts and authentication strength policies. This simplifies strong, phishing-resistant authentication for users.

The Impact

Users relying solely on device-bound MFA methods are affected, with a reduced risk of MFA fatigue but a potential for device-loss lockout.

  • End Users: Reduced friction for MFA, but increased risk of lockout if their primary device is lost or unavailable.
  • Security Team: Improved MFA posture by fully leveraging phishing-resistant methods, but requires communication on portable method registration.
  • Admins: Simplified MFA management by reducing the need for multiple method registrations per user.
  • Organisations: Enhanced security posture through broader adoption of phishing-resistant MFA.

The Action

  1. Review existing Conditional Access policies that enforce MFA to ensure they align with this change.
  2. Communicate to users the importance of registering a portable MFA method (e.g., Microsoft Authenticator, FIDO2 Security Key) for device loss scenarios.
  3. Update user onboarding documentation to recommend portable MFA registration alongside WHfB/macOS PSSO.
  4. Monitor Entra ID sign-in logs for MFA success rates and method usage to identify any unexpected trends.

Domain: Entra · Impact: medium · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907