You have a new laptop rollout, a new hire, or a Mac coming through setup. Everything looks normal, then the user hits a wall at the exact moment they try to set up Windows Hello for Business or macOS Platform SSO.

If you use Conditional Access to control who can register security information, there’s a July 2026 change that can turn this into a real support headache unless you plan for it.

What’s changing in July 2026, and why it matters

Starting July 6, 2026, Microsoft Entra Conditional Access policies that target the user action Register security information can be evaluated during:

  • Windows Hello for Business (WHfB) credential registration
  • macOS Platform SSO credential registration

Microsoft’s rollout is scheduled to begin July 6, 2026 and complete by July 13, 2026.

Why you should care as an operations leader: enrolment is a “first day” experience. If your security policies accidentally block registration, your team loses time, IT gets flooded, and users start looking for workarounds.

This change is also logical. Microsoft is closing a gap where those registration flows required MFA by default, but didn’t necessarily honour the same Conditional Access rules you use for other registration experiences.

The policies most likely to block enrolment

The tricky part is not the idea of Conditional Access. It’s the edge cases. Registration is different from normal sign-in because many users are setting up their first strong method.

Here are the usual culprits to review before July 6.

  • Trusted locations requirements. If your registration policy requires a trusted network location, a user trying to enrol from home, a hotel, or a client site can get blocked. That’s especially painful during device setup.

  • Authentication strength set too high for “bootstrap.” If you require an authentication strength like “phishing-resistant MFA” for registration, you need to be sure users already have a method that can satisfy it. Otherwise you can create a catch-22 where they must use a method they have not enrolled yet.

  • Multiple registration policies stacking. If more than one Conditional Access policy targets Register security information, users may need to satisfy all applicable grant controls. That can turn into an unexpected extra prompt, or an outright block.

  • Device or platform conditions that don’t match reality. If you use device platform conditions, make sure your registration experience still fits. A Mac enrolling Platform SSO during setup is not the same as a user signing into Outlook later.

  • A missing “break glass” path for enrolment support. If you don’t have a controlled way to help a user enrol when they are stuck, your helpdesk ends up improvising. That’s when bad exceptions creep into production.

A quick way to find the policies you need to review

You’re looking for Conditional Access policies that target the user action Register security information.

In plain terms, these are the policies you created to control when users can register MFA methods and related security info.

As you review each one, focus on two questions:

  1. Can a brand new user, on a brand new device, realistically meet these requirements?
  2. Can a travelling or remote user meet these requirements without calling IT?

If the answer is “no” to either, you probably need a pilot plan and an enrolment path.

Plan a pilot that tells you the truth (not the happy path)

A good pilot is not “IT enrols a device on the office network.” You want to test the situations that create tickets.

Pick a small group (5 to 15 people) that includes:

  • One remote-first user. Someone who will enrol from home on a normal residential ISP.
  • One frequent traveller. Someone likely to be on public Wi-Fi.
  • A mix of Windows and macOS. Because WHfB and Platform SSO are both in scope.
  • At least one non-technical user. If your instructions only work for power users, they’re not ready.

During the pilot, document exactly what users see:

  • What prompts appear
  • Whether they hit a block
  • What the helpdesk had to do to resolve it

Then adjust policies and instructions until a normal user can complete enrolment in a predictable way.

Give users a clear enrolment path that still meets your security goals

Your goal is simple: users should be able to enrol WHfB or Platform SSO without weakening your standards around MFA and network trust.

Here’s what that looks like in practice.

  • Decide what “good enrolment” means. For many growing businesses, a reasonable target is: users enrol WHfB on Windows, and Platform SSO on Macs, and they can satisfy MFA requirements without using SMS.

  • Use a controlled bootstrap method when needed. Microsoft’s Temporary Access Pass (TAP) is designed for onboarding and enrolment scenarios, including passwordless methods. It can give you a way to get a user through initial setup without leaving long-term exceptions in Conditional Access.

  • Be explicit about location expectations. If you truly require enrolment only from trusted locations, say that in the instructions up front. “You must be on the office network or VPN before you start.” If you do not require it, do not imply that users should wait until they are in the office.

  • Write the helpdesk script before the tickets arrive. Your support team should have a short checklist for a blocked enrolment, including what policy is likely in play and what approved workaround to use.

  • Keep the experience consistent across Windows and Mac. Users do not care that WHfB and Platform SSO are different technologies. They only care that “setup worked on my last laptop.” Your internal guidance should feel like one process.

A practical checklist to run this week

If you want a simple action list, use this.

  • Inventory your registration policies. Identify every Conditional Access policy that targets Register security information.
  • Review grant controls with enrolment in mind. Pay special attention to authentication strength and trusted locations.
  • Run a pilot before July 6, 2026. Include remote and non-technical users.
  • Decide your bootstrap approach. If you will use TAP for stuck enrolments, define who can issue it and how long it lasts.
  • Update user instructions. Make them short, specific, and written for someone who just wants to start work.

Want a smoother rollout? We can help

This July 2026 change is a good one, but it does mean your Conditional Access policies can now affect device credential registration in ways you might not have tested.

If you would like help reviewing your Conditional Access policies, running a pilot, and writing a clean enrolment path for Windows Hello for Business and macOS Platform SSO, the Flexnet Networks team can help you get it in place.

Sources