๐๐จ๐ฌ๐ญ ๐๐๐ฆ๐ข๐ง๐ฌ ๐๐ฌ๐ฌ๐ฎ๐ฆ๐๐ ๐๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ ๐๐๐๐๐ฌ๐ฌ ๐๐ฅ๐ซ๐๐๐๐ฒ ๐ฉ๐ซ๐จ๐ญ๐๐๐ญ๐๐ ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐๐ฅ๐ฅ๐จ ๐ซ๐๐ ๐ข๐ฌ๐ญ๐ซ๐๐ญ๐ข๐จ๐ง.
โ It didn’t.
If you have Conditional Access policies targeting “Register security information”, they currently aren’t evaluated when users register:
โข Windows Hello for Business (WHfB)
โข macOS Platform SSO credentials
That means requirements like Authentication strength and trusted locations haven’t been enforced during these registration flows.
๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐ข๐ฌ ๐ง๐จ๐ฐ ๐๐ฅ๐จ๐ฌ๐ข๐ง๐ ๐ญ๐ก๐๐ญ ๐ ๐๐ฉ.
Starting July 6, 2026, users registering WHfB or macOS Platform SSO credentials will need to satisfy your Conditional Access requirements before enrollment can complete.
๐ Device setup may fail if users can’t meet policy requirements.
๐ New authentication prompts may appear during enrollment.
๐ Users may need an existing FIDO2 key, Microsoft Authenticator approval, or access from a trusted location.
Before the rollout reaches your tenant:
โข Review Conditional Access policies targeting “Register security information”
โข Check authentication strength and grant controls
โข Test in report-only mode
โข Update helpdesk documentation
Sometimes the most important security updates aren’t new featuresโthey’re fixes for assumptions we didn’t realize were wrong.