Microsoft Entra: Windows Hello for Business and macOS Platform Single Sign-on can now be used as a second factor for MFA
🚨 The Signal: Windows Hello for Business and macOS Platform SSO now fully satisfy MFA as a second factor, removing the need for an additional passkey for step-up prompts and authentication strength policies. This simplifies strong, phishing-resistant authentication for users.
The Impact
Users relying solely on device-bound MFA methods are affected, with a reduced risk of MFA fatigue but a potential for device-loss lockout.
- End Users: Reduced friction for MFA, but increased risk of lockout if their primary device is lost or unavailable.
- Security Team: Improved MFA posture by fully leveraging phishing-resistant methods, but requires communication on portable method registration.
- Admins: Simplified MFA management by reducing the need for multiple method registrations per user.
- Organisations: Enhanced security posture through broader adoption of phishing-resistant MFA.
The Action
- Review existing Conditional Access policies that enforce MFA to ensure they align with this change.
- Communicate to users the importance of registering a portable MFA method (e.g., Microsoft Authenticator, FIDO2 Security Key) for device loss scenarios.
- Update user onboarding documentation to recommend portable MFA registration alongside WHfB/macOS PSSO.
- Monitor Entra ID sign-in logs for MFA success rates and method usage to identify any unexpected trends.
Domain: Entra · Impact: medium · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907