Microsoft is continuing its move towards stronger, phishing-resistant authentication in Microsoft 365 and Microsoft Entra.
A new Microsoft Entra change will expand the way Windows Hello for Business and macOS Platform SSO can be used to satisfy multifactor authentication requirements.
For businesses already using managed Windows PCs or Macs, this could make secure sign-in simpler for users while reducing the need for additional authentication prompts.
Windows Hello for Business already uses a device-bound cryptographic credential combined with a PIN or biometric gesture, making it a form of phishing-resistant two-factor authentication. Microsoft’s macOS Platform SSO provides a similar approach on managed Macs, using hardware-backed credentials stored in the Secure Enclave.
The upcoming Entra change is intended to allow these methods to be recognised more directly as standalone MFA factors in supported authentication scenarios.
For IT administrators, the change is another sign that Microsoft is moving away from traditional passwords and weaker verification methods towards authentication that is tied securely to the user’s device.
What is Windows Hello for Business?
Windows Hello for Business allows users to sign in to a managed Windows device using a PIN, fingerprint or facial recognition instead of entering their Microsoft 365 password each time.
Importantly, the PIN or biometric is not simply replacing one password with another.
Windows Hello for Business creates a cryptographic credential that is tied to the individual device. The credential cannot simply be copied from the device and reused by an attacker elsewhere.
Microsoft considers Windows Hello for Business a two-factor authentication method because it combines:
-
something the user has — the registered device and its protected private key
-
something the user knows or is — such as a PIN, fingerprint or facial recognition
This makes Windows Hello for Business significantly more resistant to phishing than traditional password-based authentication.
What is macOS Platform SSO?
Microsoft provides a similar capability for managed Apple Mac devices through Platform Single Sign-On, commonly referred to as Platform SSO.
When Platform SSO is configured using the Secure Enclave authentication method, the Mac creates a hardware-bound cryptographic credential that Microsoft Entra can use for authentication.
Users can then use features such as Touch ID as part of a passwordless sign-in experience while Microsoft Entra handles authentication to supported Microsoft 365 applications and services.
Microsoft describes the Secure Enclave implementation as phishing-resistant and based on the same underlying approach used by Windows Hello for Business.
This means organisations managing both Windows and Mac devices can increasingly move towards a consistent, passwordless authentication model across both platforms.
What Does It Mean for Windows Hello to Count as MFA?
Multifactor authentication does not necessarily mean entering a password and then typing in a six-digit code.
What matters is that authentication relies on more than one independent factor.
With Windows Hello for Business, the authentication process combines the registered device and its protected cryptographic credential with something the user knows or is, such as a PIN, fingerprint or facial recognition.
This is why Windows Hello for Business can provide strong multifactor authentication without requiring the user to approve a separate Microsoft Authenticator notification every time they sign in.
The same principle applies to supported macOS Platform SSO configurations, where Microsoft Entra can use a hardware-backed credential stored securely on the Mac.
What will users actually notice?
For businesses using these technologies correctly, the most noticeable change should be a smoother sign-in experience.
A user signing in with Windows Hello or a properly configured Mac may be able to satisfy an MFA requirement without being asked to complete an additional authentication step.
That does not mean Microsoft is weakening MFA.
In fact, Microsoft is moving in the opposite direction. Device-bound and phishing-resistant authentication methods are much harder for attackers to steal or trick a user into approving than traditional passwords, SMS codes or some forms of push authentication.
This fits with Microsoft's wider move away from SMS and voice authentication. We have covered that separately in our guide, Microsoft Is Ending SMS MFA – What Microsoft 365 Users Need to Do Before February 2027.
Does this mean you can turn off other MFA methods?
No. Businesses should not treat this change as a reason to remove alternative authentication or recovery methods without first reviewing their Microsoft Entra configuration.
Windows Hello for Business and Platform SSO are device-based authentication methods. Organisations still need to consider situations such as:
- a user losing or replacing their device
- a device being rebuilt or re-enrolled
- users needing to sign in from another approved device
- administrator and emergency access accounts
- authentication policies that require specific authentication strengths
If you are unsure whether MFA is configured consistently across your Microsoft 365 users, see our practical guide on how to check Microsoft 365 MFA is enabled for all users.
It is also worth reviewing the wider tenant rather than looking at MFA in isolation. Our Microsoft 365 security hardening guide covers other controls businesses should review around account security, sharing and Microsoft 365 configuration.
How secure is your Microsoft 365 environment?
Authentication is only one part of Microsoft 365 security. MFA, administrator accounts, device security, email protection, sharing, backups and licensing all need to work together.
Take the free KES Microsoft 365 Security Assessment →
It takes around 3–5 minutes and helps identify areas of your Microsoft 365 setup that may deserve closer attention.