HomeIntelligenceBrief
BREACH BRIEF🟡 Medium Advisory

Microsoft Entra ID Removes Extra MFA Step for Windows Hello and macOS PSSO Users

Microsoft Entra ID will treat Windows Hello for Business and macOS Platform Single Sign‑On as sufficient MFA credentials, dropping the extra passkey requirement. The shift impacts SOC 2 logical‑access controls and requires updated evidence and mitigation for device‑bound MFA scenarios.

LiveThreat™ Intelligence · 📅 August 10, 2026· 📰 helpnetsecurity.com
🟡
Severity
Medium
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Microsoft Entra ID Removes Extra MFA Step for Windows Hello and macOS PSSO Users

What Happened — Microsoft announced that, beginning October 2026, Entra ID will treat Windows Hello for Business (WHfB) and macOS Platform Single Sign‑On (PSSO) as sufficient MFA credentials, eliminating the need for an additional passkey or authenticator during primary sign‑in. The change applies to all worldwide and GCC tenants and requires no admin configuration.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Logical Access) expects documented, multi‑factor authentication controls; a shift in MFA handling must be reflected in your access‑control policies and evidence collection.
  • Continuous‑compliance programs need to capture the new device‑bound MFA state as audit evidence, and verify that step‑up MFA policies (e.g., Authentication Strength) still enforce stronger checks where required.
  • The device‑bound nature of WHfB/PSSO introduces a potential “single‑device” gap; auditors will look for documented mitigation (portable MFA methods) and proof that users can satisfy MFA from alternate devices.

Who Is Affected — Enterprises using Microsoft Entra ID, particularly those with BYOD or remote‑work models, across technology, finance, healthcare, and government sectors.

Recommended Actions

  • Review and update your SOC 2 access‑control policies to include WHfB and macOS PSSO as MFA‑eligible credentials.
  • Ensure Authentication Strength and step‑up MFA policies are still enforced for high‑risk actions.
  • Require users to register a portable MFA method (e.g., synced passkey or Microsoft Authenticator) and capture the registration as evidence in your compliance repository.
  • Update your continuous‑monitoring dashboards to log device‑bound MFA usage and any MFA failures from secondary devices.

Source: Help Net Security

Technical Notes — No new CVEs; the change is a configuration update (MC1450134) that treats device‑bound credentials as MFA‑capable. The only operational caveat is that users may be unable to complete MFA from a device that does not hold the credential, prompting a need for secondary, portable MFA factors. Source: same article

📰 Original Source
https://www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →