ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 252/253 feeds/APIs · 391/391 docs · synced 00:24 UTC Customize Public modeDiscuss ChangeIntel on Discord

System-preferred authentication

This page's changes and edits · All guidance changes

Microsoft's edit ·

Add WHfB/macOS PSSO first-factor behavior and federated users FAQ

Microsoft's commit message in MicrosoftDocs/entra-docs · commit 5330b0d · +16 −0 lines · also on GitHub

⋯ 43 unchanged lines
4444 - When you change the policy for a target group, the change might not take effect on the user's very next sign-in. It applies to all subsequent sign-ins after that.
4545 - Conditional Access policy is validated only for second-factor authentication and doesn't apply to first-factor authentication. Authentication happens first, and then Conditional Access evaluates authorization. System-preferred authentication doesn't override Conditional Access policies or authentication strength requirements.
4646
47 +### Windows Hello for Business and macOS Platform SSO at first-factor sign-in
48 +
49 +Windows Hello for Business and macOS Platform SSO are device-bound passkeys that work only as a first factor. Because the **Microsoft managed** state applies system-preferred authentication at the first factor, these credentials can be offered before the password.
50 +
51 +To avoid prompting users for a device-bound credential that they don't use or can't complete on their current device, system-preferred authentication offers Windows Hello for Business or macOS Platform SSO at the first factor only when the user most recently signed in with a passkey. The behavior depends on which passkeys the user registered:
52 +
53 +- If the user has a passkey other than Windows Hello for Business or macOS Platform SSO, system-preferred authentication prompts for the passkey at the first factor, just as it already prompts for that passkey at second-factor sign-in.
54 +- If the user's only registered passkey is Windows Hello for Business or macOS Platform SSO, and the user most recently signed in with a passkey, system-preferred authentication prompts for passkey sign-in at the first factor.
55 +- If the user's only registered passkey is Windows Hello for Business or macOS Platform SSO, and the user's most recent sign-in wasn't with a passkey, system-preferred authentication skips it at the first factor and prompts the next highest-ranked method in the user's credential order instead.
56 +
57 +Users can always select **Sign in another way** to choose a different registered method.
58 +
4759 ## Enable system-preferred authentication in the Microsoft Entra admin center
4860
4961 By default, system-preferred authentication is Microsoft managed for all users.
⋯ 96 unchanged lines
146158 ### How does system-preferred authentication affect the NPS extension?
147159
148160 System-preferred authentication doesn't affect users who sign in by using the Network Policy Server (NPS) extension. Those users don't see any change to their sign-in experience.
161 +
162 +### How does system-preferred authentication work for federated users?
163 +
164 +For federated users, first-factor sign-in is unchanged. System-preferred authentication doesn't apply at the first factor, so federated users continue to be routed to their external identity provider to sign in. System-preferred authentication applies only to second-factor authentication for these users.
149165
150166 ### How does system-preferred authentication affect first-factor sign-in?
151167
⋯ 12 unchanged lines

Microsoft's Markdown source from MicrosoftDocs/entra-docs, © Microsoft Corporation, under MIT. Changed lines with up to 3 unchanged lines around each; ChangeIntel kept this copy 9 Oct 21:34 UTC. The commit date is when the source changed, which can be hours or days before Learn published it.

ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 10 Oct 00:24 UTC · 252 of 253 readable · documentation 391/391 current