On a hybrid-joined, domain-managed device where Windows Hello for Business suddenly becomes unavailable after reinstalling Windows and reusing the same device name, focus on restoring a healthy Windows Hello/biometrics configuration and verifying that the platform requirements are met.
Use the following sequence (IT/admin steps):
- Verify Windows Hello sign-in options are enabled
- On the device, open Settings > Accounts > Sign-in options.
- Under Manage how you sign in to your device, confirm that Windows Hello Face, Windows Hello Fingerprint, and Windows Hello PIN are present and not greyed out.
- If PIN is failing or repeatedly prompting to set up again, remove and recreate it:
- On the lock screen, go to Sign-in options and choose to remove the PIN, then add it again. This triggers a PIN reset and can restore PIN functionality.
- If prompted again to create a PIN after already having one, this can be due to security updates or system changes; recreate the PIN and then test Hello again.
- Re-enroll biometrics from Windows If face or fingerprint options show but do not work:
- Sign in with the password.
- Go to Settings > Accounts > Sign-in options.
- For each non-working method:
- Remove the existing enrollment.
- Re-enroll:
- For fingerprint: under Fingerprint recognition (Windows Hello) select Add a finger and capture multiple angles of the finger.
- For face: under Windows Hello Face, use Improve recognition or set up again.
- Check biometric hardware and drivers If face/fingerprint entries are missing or show “We couldn’t find a fingerprint scanner compatible with Windows Hello Face/Fingerprint”:
- Open Device Manager.
- Expand Biometric devices.
- For the camera or fingerprint sensor:
- Right-click > Uninstall device.
- Restart the device so Windows reinstalls the driver.
- After restart, return to Sign-in options and check if Windows Hello Face/Fingerprint are available and working.
- Validate platform security (VBS and isolation components) For Windows Hello Enhanced Sign-in Security scenarios:
- Open System Information (msinfo32).
- In System Summary, confirm Virtualization Based Security is listed as Running.
- In System Information > Software Environment > Running Tasks, confirm
bioiso.exeandngciso.exeare running.- If VBS is not running or these processes are missing, the device may not meet Enhanced Sign-in Security requirements and Hello biometrics can fail.
- Restart the Windows Biometric Service and reset PIN container If biometrics still fail:
- In Settings > Accounts > Sign-in options, remove the PIN.
- Open an elevated Command Prompt.
- Run:
net stop wbiosrvc && net start wbiosrvc - Reboot, then set up the PIN again and test Hello Face/Fingerprint.
- Check for policy conflicts (especially in hybrid/domain) On domain-joined devices, Group Policy can block or partially break Windows Hello:
- Confirm that Interactive logon: Do not display last user name is not causing issues with facial recognition at logon. When this policy is Enabled, facial recognition logon to the domain can fail, even if PIN and fingerprint still work and face can unlock the device after sign-in.
- In Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options, set:
- Interactive logon: Do not display last user name to Disabled (or ensure it is not enforced as Enabled via domain GPO), then test Windows Hello logon again after a reboot.
- Surface- or device-specific checks (if applicable) If using a Surface or a device with a fingerprint power button:
- Ensure the fingerprint reader or Fingerprint Power Button LED is on and the sensor is clean and dry.
- For detachable keyboards with fingerprint readers, detach and reattach the keyboard, then test again.
- If the issue persists across multiple users/devices Because another user in the same hybrid environment has the same problem, this may be due to a tenant-wide or domain-wide configuration (GPO, security baseline, or Hello for Business policy). In that case:
- Compare a working device’s Sign-in options, Device Manager (Biometric devices), and System Information (VBS and running tasks) with the affected devices.
- Review recent Group Policy or security baseline changes that might affect Windows Hello for Business or Enhanced Sign-in Security.
- If all local steps fail and hardware is healthy, file feedback via Feedback Hub from an affected device with logs while reproducing the failure.
References: