System-preferred authentication
Microsoft's edit ·
Microsoft's commit message in MicrosoftDocs/entra-docs · commit 5330b0d · +16 −0 lines · also on GitHub
⋯ 43 unchanged lines
4444
- When you change the policy for a target group, the change might not take effect on the user's very next sign-in. It applies to all subsequent sign-ins after that.
4545
- Conditional Access policy is validated only for second-factor authentication and doesn't apply to first-factor authentication. Authentication happens first, and then Conditional Access evaluates authorization. System-preferred authentication doesn't override Conditional Access policies or authentication strength requirements.
4646
47
+### Windows Hello for Business and macOS Platform SSO at first-factor sign-in
48
+
49
+Windows Hello for Business and macOS Platform SSO are device-bound passkeys that work only as a first factor. Because the **Microsoft managed** state applies system-preferred authentication at the first factor, these credentials can be offered before the password.
50
+
51
+To avoid prompting users for a device-bound credential that they don't use or can't complete on their current device, system-preferred authentication offers Windows Hello for Business or macOS Platform SSO at the first factor only when the user most recently signed in with a passkey. The behavior depends on which passkeys the user registered:
52
+
53
+- If the user has a passkey other than Windows Hello for Business or macOS Platform SSO, system-preferred authentication prompts for the passkey at the first factor, just as it already prompts for that passkey at second-factor sign-in.
54
+- If the user's only registered passkey is Windows Hello for Business or macOS Platform SSO, and the user most recently signed in with a passkey, system-preferred authentication prompts for passkey sign-in at the first factor.
55
+- If the user's only registered passkey is Windows Hello for Business or macOS Platform SSO, and the user's most recent sign-in wasn't with a passkey, system-preferred authentication skips it at the first factor and prompts the next highest-ranked method in the user's credential order instead.
56
+
57
+Users can always select **Sign in another way** to choose a different registered method.
58
+
4759
## Enable system-preferred authentication in the Microsoft Entra admin center
4860
4961
By default, system-preferred authentication is Microsoft managed for all users.
⋯ 96 unchanged lines
146158
### How does system-preferred authentication affect the NPS extension?
147159
148160
System-preferred authentication doesn't affect users who sign in by using the Network Policy Server (NPS) extension. Those users don't see any change to their sign-in experience.
161
+
162
+### How does system-preferred authentication work for federated users?
163
+
164
+For federated users, first-factor sign-in is unchanged. System-preferred authentication doesn't apply at the first factor, so federated users continue to be routed to their external identity provider to sign in. System-preferred authentication applies only to second-factor authentication for these users.
149165
150166
### How does system-preferred authentication affect first-factor sign-in?
151167
⋯ 12 unchanged lines
Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.