Microsoft is fundamentally shifting how enterprise authentication works within Entra ID. According to the announcement, the identity platform will soon recognize Windows Hello for Business and macOS Passkey Single Sign-On (PSSO) as standalone multi-factor authentication (MFA) factors. This Entra ID MFA update means organizations can configure these biometric and cryptographic methods to satisfy the second-step verification requirement on their own, without forcing users to reach for a secondary code or authenticator app.
What Exactly Is Changing
Historically, Windows Hello and Apple’s passkey implementation have served as primary authentication methods. When Entra ID enforced MFA policies, users typically had to complete the biometric or PIN check and then provide an additional verification step, such as a push notification, SMS code, or TOTP token. Under the new configuration, both methods will be classified as valid second factors within the conditional access and authentication strength policies. This aligns with the FIDO2 standard, which has long treated public-key cryptographic proofs as equally strong as traditional MFA methods.
Why This Entra ID MFA Update Matters
The move addresses a well-documented friction point in enterprise security: MFA fatigue and phishing resistance. Security researchers have repeatedly shown that while push notifications and SMS codes significantly reduce account compromise, they remain vulnerable to relay attacks and social engineering. Passkeys and Windows Hello, by contrast, rely on device-bound cryptographic keys that cannot be phished. By elevating these methods to standalone MFA status, Microsoft is effectively telling administrators that a properly configured passkey or Hello credential already meets the security threshold for a second factor. This reduces the attack surface while cutting down on the login steps that often drive users toward workarounds.

What This Means for You
If you manage an Entra ID-joined fleet, this update simplifies policy design. You will no longer need to chain a primary credential with a secondary MFA method for users who already authenticate via Windows Hello or macOS PSSO. For everyday users, the change translates to fewer prompts during sign-in. Instead of tapping a biometric sensor and then waiting for an authenticator app to buzz, you will complete a single, secure verification that satisfies both the primary and secondary requirements. It also reinforces Microsoft’s long-standing push toward passwordless authentication, making cryptographic keys the default rather than an optional upgrade.
How to Get It
The update will roll out through the standard Entra ID deployment pipeline. Administrators will need to adjust their authentication strength policies and conditional access rules to explicitly permit Windows Hello and macOS PSSO as standalone MFA factors. Microsoft has indicated that the feature will be available to Entra ID customers through the existing policy configuration portal, meaning no separate software installation or version upgrade is required. Organizations should test the new authentication strength settings in a pilot group before applying them company-wide, as policy precedence can override individual factor configurations.

What to Watch For
While the announcement focuses on Windows and macOS, enterprise environments running other platforms will likely continue relying on traditional MFA methods until equivalent passkey support matures. Additionally, organizations with legacy applications that do not support FIDO2 or modern authentication flows should verify compatibility before enforcing the new authentication strength policies. As Microsoft continues to align Entra ID with industry-wide passwordless standards, expect similar elevation of other cryptographic authentication methods in future updates.
Source: Neowin
Over to you: Will your organization switch to passwordless authentication now that Windows Hello and passkeys count as full MFA, or will you keep traditional codes as a backup?



