Microsoft Entra: Windows Hello for Business and macOS Platform Single Sign-on can now be used as a second factor for MFA Beta

365 Roadmap Tracker Item 568076

Data as of 2 hours ago (9 September 2026)

Status In development
Release month October 2026
Release ring General Availability
Products Microsoft Entra
Cloud instances GCCWorldwide
Platforms DesktopMac

Description

Windows Hello for Business (WHfB) and macOS Platform SSO (macOS PSSO) can now satisfy multifactor authentication as a standalone second factor. Previously, these methods only counted as MFA during primary sign-in, and users needed a separate passkey to complete step-up prompts, Authentication Strength policies, and sign-in frequency checks. With this change, WHfB and macOS PSSO work on their own for those scenarios, so more of your users can rely on strong, phishing-resistant sign-in without registering an extra method. What you need to know: Users who have only WHfB or macOS PSSO are now treated as MFA-capable and will no longer be automatically prompted to register another method. Because WHfB and macOS PSSO are tied to a specific device, we recommend having users register a portable method, such as a passkey or Microsoft Authenticator, during onboarding so they can complete MFA from any device.

Change history

Added to the roadmap 11 August 2026. Tracked here since 1 September 2026. Earliest target we recorded: October 2026 (since tracked — Microsoft may have moved it before we started watching).

Nothing has changed on this item since tracking began on 1 September 2026. Changes appear here as Microsoft updates the feed.

View on Microsoft's roadmap

Back to all roadmap items · What changed recently