Windows Hello PIN is unavailable or must be reset

What to do first

Windows Hello PIN is unavailable or must be reset. TPM state, account authentication, organization policy, or the PIN container may be inconsistent. Record the current state before changing it, use only the supported Windows path described below, and verify the same operation again after any required restart.

This is a general troubleshooting guide, not an announcement of a current outage.

Affected products and symptoms

Product
Windows Hello
Versions and conditions
Windows 11 (confirm the edition and hardware requirements for the feature)
Error codes and identifiers
0x80090016

Symptoms

  • Windows Hello PIN is unavailable or must be reset.
  • The same condition can persist after a retry or restart.

Causes and conditions

TPM state, account authentication, organization policy, or the PIN container may be inconsistent.

Before you start

  • Save open documents and allow time for a Windows restart if required.
  • Run administrative actions only on a personally managed PC or with administrator approval.
  • Save the diagnostic command output so the before and after states can be compared.

Precautions

  • Do not bulk-delete registry entries, system folders, credentials, or storage metadata.
  • Do not run unofficial scripts or unknown drivers with administrator rights.
Windows Hello troubleshooting sequence: Ensure another sign-in method is available; Check the state with dsregcmd; Repair through the supported path; Lock the screen and test the new PIN; Check sign-in after restarting
Procedure overview created by FaultNote. Read the precautions and full instructions before changing settings. Read the full steps

Step-by-step instructions

  1. 01

    Ensure another sign-in method is available

    #

    At the sign-in screen, check whether Sign-in options offers a password. Confirm access to the email address or phone used to verify your Microsoft account. Contact IT if identity verification for a work account cannot proceed.

  2. 02

    Check the state with dsregcmd

    #

    Confirm that password sign-in and Internet access work, then record dsregcmd /status. On a managed PC, give the output to the administrator rather than changing join or policy state.

  3. 03

    Repair through the supported path

    #

    Open Settings > Accounts > Sign-in options > PIN (Windows Hello), choose I forgot my PIN, complete identity verification, and create a new PIN.

  4. 04

    Lock the screen and test the new PIN

    #

    After recreating the PIN, save your documents and press Windows key + L to lock the screen. Verify that the new PIN signs you in. Clearing the TPM or manually deleting the NGC folder is not required for this procedure.

  5. 05

    Check sign-in after restarting

    #

    After confirming your alternative password is available, restart and sign in with the new PIN. If Windows asks you to recreate it again, report the account type and on-screen error to IT.

Check the result

  • The feature starts, connects, or completes without the original error.
  • The verification command reports the expected enabled, healthy, or connected state.
  • The result remains correct after a Windows restart and no new matching critical event appears.

If the problem continues

  • If the same code persists, provide the full message, Windows build, command output, and occurrence time to the PC administrator or Microsoft Support.
  • If hardware requirements, organization policy, or server settings are responsible, ask the owner to make the change instead of bypassing it on the client.

Scope of this guide

Troubleshooting guide — Restore the feature so it starts, connects, or completes normally and passes the same verification after a Windows restart.

Frequently asked questions

Why is I forgot my PIN missing?

It can be unavailable for a local account or while offline. Choose Sign-in options, use the password, then reset the PIN in Settings.

Should I delete the NGC folder?

No. Manual deletion can damage permissions and Windows Hello. Use the supported PIN reset flow first.

Official sources and dates

Source publication or resolution date: Not specified. Sources checked: 2026-09-05. The check date is not the date the problem first occurred. Interface labels can vary between versions and display languages.

Related troubleshooting guides

← Search English guides