A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If an alternate sign-in method still works, reset the PIN from inside Windows:
- Sign in with another credential.
- Open Settings > Accounts > Sign-in options.
- Select PIN (Windows Hello) > I forgot my PIN.
- Complete the authentication steps and create a new PIN.
If the PIN does not work at the lock screen:
- On the sign-in screen, open Sign-in options.
- Select the PIN pad icon.
- Select I forgot my PIN.
- Authenticate with one of the available methods and complete the reset flow.
If Windows crashes during PIN creation or change, try these supported mitigations first:
- Sign out and sign back in, then try creating or resetting the PIN again.
- Check for system updates.
- If PIN creation shows an error, sign out and sign back in before retrying.
Important:
- On Microsoft Entra hybrid joined devices, destructive PIN reset requires corporate network connectivity to domain controllers.
- If AD FS is used, connectivity to federation services is also required.
- For Key Trust on Microsoft Entra hybrid joined devices, destructive PIN reset from above the lock screen is not supported.
- Nondestructive PIN reset requires the Microsoft PIN reset service and the Use PIN Recovery client policy to be enabled.
To verify whether nondestructive PIN reset is enabled on the device, run:
dsregcmd /status
Check the CanReset value in the user state:
- DestructiveOnly = only destructive PIN reset is enabled
- DestructiveAndNonDestructive = nondestructive PIN reset is enabled
If the crash happens every time during the reset flow, use another sign-in method to get into Windows first, then retry from Settings instead of the lock screen.