That Fingerprint is too similar to one that's already set up.

Woody Chiu at RASI 251 Reputation points
2023-11-02T15:09:34.74+00:00

Just some background here first. We have a hybrid setup, AD and AAD using Azure AD Connect. Windows Hello for Business Cloud Trust has been set up and working fine. However, for whatever reason, some users sometimes are not able to sign in to Windows with either a PIN or fingerprint. Since we enforced users by Conditional Access to sign in with phishing-resistant methods which are either PIN or Fingerprint in order to be able to connect the Palo Alto VPN to our Head Office, they will not be able to connect VPN if they are not signing in to with either of the methods. One morning, a user's registered PIN and fingerprint in Windows 11 suddenly were not working. He managed to sign in with a password first and reset his PIN successfully. He then tried to re-register his fingerprint by successfully removing the current one inside the Sign-in Options dialog. However, when he tried to start the fingerprint setup to register the same finger he used before, he kept getting this message " Sorry, something went wrong. That fingerprint is too similar to one that's already set up. Try a different finger." he wanted to use the same finger. So, we removed all the .dat files inside C:\Windows\System32\WinBioDatabase while the Windows Biometric Service was stopped and then started the service, then had him do the fingerprint setup again. Unfortunately, he still encountered the same message " Sorry, something went wrong. That fingerprint is too similar to one that's already set up. Try a different finger." Would that be caused by the initial removal of his fingerprint while the VPN was not connected so that a copy of the previously registered fingerprint ID still existed in the Azure AD?

Is there an ultimate solution to reset his biometric setup so that he can register his same index finger?

CS

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Client for IT Pros | User experience | Other
Microsoft Security | Intune | Other
Microsoft Security | Microsoft Entra | Other

7 answers

Sort by: Newest
  1. Nagappan Veerappan 656 Reputation points Microsoft Employee
    2023-12-06T21:13:36.38+00:00

    Finger print or facial hash data stores locally on the device. never goes out to Azure AD.

    your Bio-matches with sensor locally unlock access to private keys stored on the device (TPM). Client sends the signed Nonce back to AAD to validate with public key registered.

    How to clear the Bio-metric data?. Please reach out to Microsoft windows team support.

    Was this answer helpful?


  2. Givary-MSFT 35,916 Reputation points Microsoft Employee Moderator
    2023-11-13T07:15:18.39+00:00

    @Woody Chiu at RASI Apologies for the delayed response, researched on your ask and also check with my team on this, if the user performed a non-destructive reset of their PIN, then their fingerprint registration was probably preserved, you could try a destructive reset by running certutil -deletehellocontainer from a standard command prompt and rebooting the machine and verify if it helps to resolve your issue.

    Let me know if you have any further questions, feel free to post back.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.