Dear abdo elbarbary,
The behavior you describe is a known limitation when Windows Hello for Business is configured with PIN‑only authentication. In this mode, the system treats the PIN as a convenience credential bound to the TPM, but it does not enforce a lock screen challenge after resume from sleep or modern standby. That is why the session unlocks automatically without prompting. When a biometric factor such as facial recognition is added, Windows enforces the credential provider sequence correctly and requires re‑authentication.
This is not a misconfiguration of power settings but rather how the credential provider stack currently handles PIN‑only scenarios. The preventive measure is to configure Windows Hello for Business with at least one additional factor, such as biometrics or a smart card, so that the lock screen is enforced after resume. If you must rely on PIN‑only, the only reliable workaround is to enforce “Require sign‑in on wake” through Group Policy (Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options > Interactive logon: Machine inactivity limit) combined with enabling “Require Windows Hello sign‑in for Microsoft accounts” in Settings. Even then, enforcement may be inconsistent on modern standby devices.
At this time, Microsoft’s guidance is to avoid PIN‑only deployments for WHFB in environments where security after resume is critical, and to use multifactor Hello configurations.
If my answer is useful for you, please hit Accept the answer to support me.
Thank you,
QQ.