Windows Hello for Business: Troubleshooting Guide (ETS Internal)

Summary

This article provides a quick fix to get people able to log in again, and details for how to reprovision the Windows Hello for Business (WHFB) PIN if necessary.

 

Issue

Users may experience authentication issues or lose access to resources (printing, file shares, etc.) after setting up a WHFB PIN. This typically occurs when the device is not added to the Hybrid Cloud Trust policy.

 

Quick Fix Steps

If a user reports issues after setting up a PIN:

Step 1 - Login with Username & Password:

  • On the login screen, select 'Sign-in options' and choose 'Username & Password'.

Step 2 - Sync Device via Company Portal:

2.1 - Open the Company Portal app.
2.2 - Click 'Settings' (gear icon).
2.3 - Select 'Sync'

Step 3 - Reboot:

  • Restart the machine and check access to resources.

Step 4 - Document In your ticket:

 

Delete & Reprovision WHFB PIN

Part A: Delete the WHFB PIN Configuration

Step 1 - Open Command Prompt as the user:

  •    Press Windows + S, type 'cmd'

Step 2 - Run this command:

  • certutil -deleteHelloContainer

 

Part B: Reprovision the PIN

Step 1 - Open the Run dialog

  • Press Windows + R

Step 2 - Enter this command:

  • ms-cxh://NTH/AADNGCONLY

Step 3 - This will launch the WHFB provisioning screen for setting up a new PIN. Walk the user through setting up a new PIN.

 

Additional Notes

Always associate the case with Problem Ticket #914345 - https://td.usnh.edu/TDNext/Apps/38/Tickets/TicketDet?TicketID=914345 

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.