Windows Hello PIN Setup Window Disappears Before Finish Entering Email

Tera Tarbet 0 Reputation points
2026-03-10T00:11:07+00:00

I have provided recorded feedback to MSFT twice now with at least a month in between and no answer. I reached out to MSFT Support and they didn't fix it.

I have used online troubleshooting resources and tried the following and neither have solved the problem:

  1. Delete NGC and restart
  2. Clear TPM and restart

This Windows Hello bug is preventing me from setting up a Windows Hello PIN and thus, I can't create a Passkey for a website now requiring Passkey and I have not been able to access a online account since November 2025. I guess next step is reporting MSFT to BBB because they still have not provided me trouble shooting steps to solve this issue and I do not want to have to back up everything and reload Windows 11. I shouldn't have to, MSFT should have all of this working correctly! Any MSFT expert able to provide me the steps to fix this Windows Hello issue?

Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-10T00:11:23.4+00:00

    Follow these steps in order, checking after each major step whether Windows Hello PIN setup works without the window closing:

    1. Remove existing Windows Hello sign-in methods
      1. Open Settings > Accounts > Sign-in options.
      2. Under PIN (Windows Hello), remove any existing PIN if it is still listed.
      3. Under Fingerprint recognition (Windows Hello) or Windows Hello Face, remove any existing enrollments.
      4. Sign out and sign back in, then try to set up the PIN again from Settings > Accounts > Sign-in options > PIN (Windows Hello).
    2. Check for common PIN-creation error conditions If an error code appears briefly before the window disappears, note it. For the following codes, use the specific mitigations:
      • 0x801C03EF (AIK certificate no longer valid) – Sign out and sign back in, then retry PIN setup.
      • 0x801C03F2 (Windows Hello key registration failed) – This indicates a directory attribute conflict (proxyAddresses). Resolve any sync conflicts as described in Duplicate Attributes Prevent Dirsync, and verify that the Mail/Email address in Microsoft Entra ID matches the primary SMTP address in the proxy address. Then retry PIN setup.
      • 0x801C044D (Authorization token doesn’t contain device ID / unable to obtain user token) – Unjoin the device from Microsoft Entra ID and rejoin. If the issue is “unable to obtain user token,” sign out and sign in again, and verify network connectivity and credentials.
      • 0x801C044E (Failed to receive user credentials input) – Sign out and sign back in, then retry.
      • 0x801C0451 (User token switch account) – Delete the Web Account Manager token broker files in %LOCALAPPDATA%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts\*.*\ and reboot, then retry PIN setup.
      • 0xC00000BB (PIN or option temporarily unavailable) – The destination domain controller does not support the login method or its KDC certificate/CRL. Use another sign-in method on this device; PIN/Hello may not be usable until the domain-side issue is fixed.
    3. General PIN troubleshooting
      • If prompted to create a PIN again after already having one, this can be due to security updates or system changes. Create the PIN again and then test.
      • If PIN creation fails without a visible error, sign out and sign back in, then attempt to create the PIN again from Settings > Accounts > Sign-in options > PIN (Windows Hello).
      • If the PIN itself later fails to work, use the I forgot my PIN option under PIN (Windows Hello) to reset it as described in Change or reset your PIN.
    4. Check Enhanced Sign-in Security and biometric services (if biometrics are also affected)
      1. Open System Information > System Summary and confirm Virtualization Based Security is listed as Running.
      2. In System Information > Software Environment > Running Tasks, confirm bioiso.exe and ngciso.exe are running. If not, the system may not meet Enhanced Sign-in Security requirements.
      3. In Settings > Accounts > Sign-in options, remove any nonfunctioning Windows Hello Face/Fingerprint enrollments and re-enroll.
      4. Open Device Manager, expand Biometric devices, uninstall the fingerprint/face sensor, then restart so Windows reinstalls the driver.
      5. Remove the PIN again from Sign-in options, open an elevated Command Prompt, and run:
              net stop wbiosrvc && net start wbiosrvc
        
        Then add the PIN again and test.
    5. If the PIN setup UI still closes immediately
      • Confirm that sign-in with password still works and that there are no domain/KDC issues (if joined to a domain or Entra ID).
      • If any of the specific error codes above appear, apply the exact mitigation for that code and then retry PIN setup.
      • If no error is visible and all steps above have been followed, the remaining supported path in similar cases has been a clean reinstall of Windows, which has resolved otherwise unfixable PIN/Hello corruption issues in practice.

    Once PIN creation succeeds, use that PIN to create and register the required passkey for the website.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.