Follow these steps in order, checking after each major step whether Windows Hello PIN setup works without the window closing:
- Remove existing Windows Hello sign-in methods
- Open Settings > Accounts > Sign-in options.
- Under PIN (Windows Hello), remove any existing PIN if it is still listed.
- Under Fingerprint recognition (Windows Hello) or Windows Hello Face, remove any existing enrollments.
- Sign out and sign back in, then try to set up the PIN again from Settings > Accounts > Sign-in options > PIN (Windows Hello).
- Check for common PIN-creation error conditions
If an error code appears briefly before the window disappears, note it. For the following codes, use the specific mitigations:
- 0x801C03EF (AIK certificate no longer valid) – Sign out and sign back in, then retry PIN setup.
- 0x801C03F2 (Windows Hello key registration failed) – This indicates a directory attribute conflict (proxyAddresses). Resolve any sync conflicts as described in Duplicate Attributes Prevent Dirsync, and verify that the Mail/Email address in Microsoft Entra ID matches the primary SMTP address in the proxy address. Then retry PIN setup.
- 0x801C044D (Authorization token doesn’t contain device ID / unable to obtain user token) – Unjoin the device from Microsoft Entra ID and rejoin. If the issue is “unable to obtain user token,” sign out and sign in again, and verify network connectivity and credentials.
- 0x801C044E (Failed to receive user credentials input) – Sign out and sign back in, then retry.
- 0x801C0451 (User token switch account) – Delete the Web Account Manager token broker files in
%LOCALAPPDATA%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts\*.*\and reboot, then retry PIN setup. - 0xC00000BB (PIN or option temporarily unavailable) – The destination domain controller does not support the login method or its KDC certificate/CRL. Use another sign-in method on this device; PIN/Hello may not be usable until the domain-side issue is fixed.
- General PIN troubleshooting
- If prompted to create a PIN again after already having one, this can be due to security updates or system changes. Create the PIN again and then test.
- If PIN creation fails without a visible error, sign out and sign back in, then attempt to create the PIN again from Settings > Accounts > Sign-in options > PIN (Windows Hello).
- If the PIN itself later fails to work, use the I forgot my PIN option under PIN (Windows Hello) to reset it as described in Change or reset your PIN.
- Check Enhanced Sign-in Security and biometric services (if biometrics are also affected)
- Open System Information > System Summary and confirm Virtualization Based Security is listed as Running.
- In System Information > Software Environment > Running Tasks, confirm
bioiso.exeandngciso.exeare running. If not, the system may not meet Enhanced Sign-in Security requirements. - In Settings > Accounts > Sign-in options, remove any nonfunctioning Windows Hello Face/Fingerprint enrollments and re-enroll.
- Open Device Manager, expand Biometric devices, uninstall the fingerprint/face sensor, then restart so Windows reinstalls the driver.
- Remove the PIN again from Sign-in options, open an elevated Command Prompt, and run:
Then add the PIN again and test.net stop wbiosrvc && net start wbiosrvc
- If the PIN setup UI still closes immediately
- Confirm that sign-in with password still works and that there are no domain/KDC issues (if joined to a domain or Entra ID).
- If any of the specific error codes above appear, apply the exact mitigation for that code and then retry PIN setup.
- If no error is visible and all steps above have been followed, the remaining supported path in similar cases has been a clean reinstall of Windows, which has resolved otherwise unfixable PIN/Hello corruption issues in practice.
Once PIN creation succeeds, use that PIN to create and register the required passkey for the website.
References: