MC1326253 High
Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration
Summary AI-generated
Conditional Access policies targeting Register security info will apply to Windows Hello for Business and macOS Platform SSO enrollments, requiring policy requirements be met before credential registration.
Suggested actions AI-generated
- Review Register security info Conditional Access policies
- Check Grant controls for registration requirements
- Verify users can meet policy during device setup
- Test with report-only mode
- Update helpdesk documentation
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1450134 (Updated) Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors
- MC1438491 Admin control for single sign-on prompts in Windows
- MC1450133 Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method
- MC1472591 Enhanced security and access controls for Outlook attachments
- MC1469555 Microsoft Entra: Optimized passkey registration campaign experience
- MC1282568 (Updated) General Availability: Microsoft Entra passkeys on Windows
Original post from Microsoft
If your organization has Conditional Access policies scoped to Register security information, those policies will now apply when users set up Windows Hello for Business (WHfB) or register macOS Platform SSO credentials.
Today, these registration flows enforce MFA, but do not evaluate your registration-targeting Conditional Access policies — meaning requirements like authentication strength, trusted locations, or other CA conditions aren't enforced when users enroll WHfB or macOS Platform SSO credentials. This change closes that gap.
Organizations without these policies aren't affected.
When this will happen
• July 6, 2026: Gradual rollout begins.
• July 13, 2026: Rollout complete for all tenants.
How this affects your organization
Users registering WHfB or macOS PSSO credentials will need to satisfy your registration-targeting Conditional Access policy requirements before completing enrollment. For example, a user might need to use an existing FIDO2 security key, approve a push notification in Microsoft Authenticator, or connect from a trusted network location — depending on what your policies require. Any Grant controls you've configured will apply.
Users who don't meet the requirements will be blocked from completing registration until the conditions are met.
Action recommended
- In Entra admin center > Protection > Conditional Access, find policies targeting Register security information.
- Review Grant controls — check what requirements users must satisfy during registration (authentication strength, trusted locations, MFA method).
- Consider whether users setting up a new device can meet your policy requirements — for example, make sure users have a FIDO2 security key or other qualifying credential available before they start device setup.
- Test with report-only mode before enforcement reaches your tenant.
- Update helpdesk docs — users may see a new authentication prompt during device setup.
If you experience issues during the rollout window (July 6–July 13), contact Microsoft Support or your account team for assistance.
Learn more: Require MFA for security info registration
Additional details from Microsoft
- Summary
- Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.