Locked out! Windows 11 will not accept password login, but there is no option to enter Win Hello PIN instead


mackintg

New member
Local time
3:08 PM
Posts
5
OS
Windows 11 v10.0.22631 Build 22631
Win 11 will not allow me to do a password login into my local account. My Password is correct (I get an appropriate error message if I intentionally enter wrong password), but login is rejected as below, with no ability to enter my Windows Hello PIN instead. I know my PIN, but the login screen offers no option to enter it.

My sense is that if I could disable the setting that is making Windows obsess about using ONLY Windows Hello to log into any account then I could fix things up from there. But I have not been able to do this.

Password error.png

Here is what I have already tried...

SAFE MODE:
This is the ONLY way for me to log in... in Safe Mode the password is accepted with no PIN required. This is how I have tried all the other corrective steps listed below, but nothing has had any effect when I reboot normally. Hence this post asking for your help!

WINDOWS/SETTINGS/ACCOUNT:

Settings > Accounts > Additional Settings >
"For improved security, only allow Windows Hello sign-in for Microsoft accounts on this device" -- SET TO OFF

NEW ACCOUNT
Settings > Accounts > Create New Account

Created a new local admin account with a password. Rebooted. New account had the same login problem... unable to login because it wants a PIN but with no UI ability to enter it.

WINDOWS SERVICES:

Windows Biometric Service - DISABLED
Web Account Manager - DISABLED

NGC FILES:

Deleted all files in C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc (in case they were corrupted) in case they were corrupted.

REGEDIT:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Settings\AllowSignInOptions set to 0

GPEDIT:

Local Computer Policy / Computer Configuration / Windows Components / Biometrics /
Allow domain users to login using biometrics - DISABLED
Allow the use of biometrics - DISABLED
Allow users to login using biometrics - DISABLED

Local Computer Policy / Computer Configuration / System / Logon /
Always use classic logon - ENABLED
Turn on convenience PIN sign in - DISABLED
Turn on security key sign in - DISABLED

Local Computer Policy / Computer Configuration / Windows Components / Windows Hello for Business
Use certificate for on-premises authentication - DISABLED
Use Windows Hello for Business - DISABLED
Use Windows Hello for Business cerificates as smart card certificates - DISABLED

User Computer Policy / User Configuration / Windows Components / Windows Hello for Business
Use Windows Hello for Busines - DISABLED
Use certificate for on-premises authentication - DISABLED

I also took the step of disabling the Group Policy Client Service entirely... this test was more involved but doable... as directed here Disabling the Group Policy Client Service in Windows

Any ideas?
 
Windows Build/Version
Windows 11 v10.0.22631 Build 22631

My Computer

System One

  • OS
    Windows 11 v10.0.22631 Build 22631
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1
    CPU
    Intel i7-1270P
    Memory
    16GB
I would like to have you run a Clean Boot.

A clean boot is a troubleshooting technique that allows you to get the computer up and running so that you can perform diagnostic tests to determine which elements of the normal boot process are causing problems.

How to perform a Clean Boot.

Warning: Disabling items in Services or Startup may leave your antivirus disabled until the process is ended. For this reason, I would suggest that you perform this process off-line.

Press the
7W6b39o.png
keys to open Run, then type msconfig in the search box. This will open System Configuration.

If you are prompted for an administrator password or for confirmation, you should enter the password or provide confirmation.

(1) Click/tap on the General tab.

(2) Click/tap on the Selective startup option.

(3) Remove the check mark in the Load startup items check box.

0JgaJnG.png


4. Click on the Services tab.

5. Place a check mark in the Hide all Microsoft services check box, this will remove the Microsoft Services from the list but will still be running.

6. Click Disable all, this will remove all of the check marks in the Services list.

yIKrmLs.png


7. Click on Apply then OK

ljHR4ZW.png


Click on Restart in the window that opens.

When the computer is restarted, it will boot normally.

If the problem does not continue after the restart, please do the following.

8. Divide the number of these startup services and programs by two, and you place checks in the first half of these, then restart the computer.

9. If the problem doesn't return in those services and programs, remove the checks and place checks in the remaining services and programs and restart the computer.

10. When you find which half the service or program is in, go on to the next step.

11. The half which has the service causing this problem, remove half of the checks as you did previously to see which half has this service. Do the same for the programs. Restart the computer.

12. If it isn't in the first half of these services and programs, do the same with the last half of the services and programs.

13. Once you have narrowed it down to the last three or four services and programs, remove the checks one at a time till you find the service or program at fault.

Once you have found the service or program, post it in your topic. Do not take any action until I suggest the next step.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
Several complaints about the same thing over on MS forum. Most of the folks found it was because of a VPN. Do you use a VPN? If so get rid of it.

I found a couple of other posts that solved it in the weirdest way I have ever heard of...turning on airplane mode. That makes absolutely no sense to me but it worked for quite a few people.

What would make sense to me is to disable your wireless (or ethernet adapter, whichever your use) Boot normally to see if your password will work.

Prove that your password is good by using another device. See if you can log in to your MS account Microsoft account | Sign In or Create Your Account Today – Microsoft
If you can, while you're there click on Security>Advanced Security options. Make sure you have multiple ways of account recovery. Another email account and your cell phone so they can send a security code.

If that or none of the suggestions already given by others do not work, backup your personal files using safe mode, Then do a system reset and remove everything or a clean install. Sorry, but a repair install will not work in safe mode.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3593
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
If it asks for PIN, Windows Hello is clearly enabled. Using 11 and Hello with a local account is atrocity. o_O
Created a new local admin account with a password. Rebooted. New account had the same login problem... unable to login because it wants a PIN but with no UI ability to enter it.

Web Account Manager - DISABLED
User Data services and Web Account Manager are required to be able to login.

Since you can boot to safe mode, do this:
Code:
takeown /s %computername% /u %username% /f "%WINDIR%\System32\utilman.exe"
icacls "%WINDIR%\System32\utilman.exe" /grant:r %username%:F
copy /y %WINDIR%\System32\cmd.exe %WINDIR%\System32\utilman.exe
takeown /s %computername% /u %username% /f "%WINDIR%\System32\sethc.exe"
icacls "%WINDIR%\System32\sethc.exe" /grant:r %username%:F
copy /y %WINDIR%\System32\cmd.exe %WINDIR%\System32\sethc.exe
That will give you CMD with SYSTEM rights at logon. You can use it to regedit, run services, change the password:
Code:
net user username password
net user username *

20240331_103251.jpg
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 3600 & No fTPM (07/19)
    Motherboard
    MSI B450 TOMAHAWK 7C02v1E & IFX TPM (07/19)
    Memory
    4x 8GB ADATA XPG GAMMIX D10 DDR4 3200MHz CL16
    Graphics Card(s)
    MSI Radeon RX 580 ARMOR 8G OC @48FPS (08/19)
    Sound Card
    Creative Sound Blaster Z (11/16)
    Monitor(s) Displays
    24" AOC G2460VQ6 (01/19)
    Screen Resolution
    1920×1080@75Hz & FreeSync (DisplayPort)
    Hard Drives
    ADATA XPG GAMMIX S11 Pro SSD 512GB (07/19)
    PSU
    Seasonic M12II-520 80 Plus Bronze (11/16)
    Case
    Lian Li PC-7NB & 3x Noctua NF-S12A FLX@700rpm (11/16)
    Cooling
    CPU Cooler Noctua NH-U12S@700rpm (07/19)
    Keyboard
    HP Wired Desktop 320K + Rabalux 76017 Parker (01/24)
    Mouse
    Logitech M330 Silent Plus (04/23)
    Internet Speed
    400/40 Mbps via RouterOS (05/21) & TCP Optimizer
    Browser
    Edge (No FB/Google) & Brave for YouTube & LibreWolf for FB
    Antivirus
    NoAV & Binisoft WFC & NextDNS
    Other Info
    Headphones: Sennheiser RS170 (09/10)
    Phone: Samsung Galaxy Xcover 7 (02/24)
I've never been in this position but, since you can log in in Safe mode, can't you do that then use
Enable or Disable Passwordless Sign-in for Microsoft Accounts - ElevenForumTutorials
Option 2 .Reg file
to disable Windows Hello so you can then log in normally with your password?

I use this procedure even though I have a Local user account so that the checkbox appears in NetPlWiz so I can set up automatic login.
Enable or Disable Automatically Sign in Account at Startup - ElevenForumTutorials


Denis
 

My Computer

System One

  • OS
    Windows 11 Home x64 Version 23H2 Build 22631.3447
Have you tried enabling the built in administrator account and then try logging in with that account?

net user administrator/active:yes
 

My Computer

System One

  • OS
    Windows 10/11
    Computer type
    Laptop
    Manufacturer/Model
    Acer
Thanks all to the suggestions above. I appreciate the help!

@FreeBooter - That took a while, but nothing lets me log in except safe mode. Anything else hits the same problem, even with all services disabled and no startup apps.

@TairikuOkami- I agree, using Windows Hello on a local account IS an atrocity! :) I have been trying to disable it for hours, including all the new suggestions from this post... but no luck, read below. If you have any other suggestions on how to disable it, that would be great so that I can log in with just my password, that would be great. I tried the net user password change you suggested but this did nothing. If I enter that new password, it continues to demand that I use Windows Hello.

@glasskuter - No, I am not using VPN. This problem occurs whether or not I am connected to a network. Yes, I can log into my Windows Account using that password, no problem. Also, if I type in a junk password when I am trying to log into my laptop, it will display an error saying the password is bad. I only get the "you must use Windows Hello" error when I enter the correct password. Also, this is the password that works OK in Safe Mode.

@Try3 ... Interesting suggestion to enable passwordless... just tried that, no effect. The "only allow Windows Hello" option in Settings/Sign-in-options have been turned off from the start. I booted in safe mode, made the regedit changes to [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PasswordLess\Device] "DevicePasswordLessBuildVersion"=dword:00000002 . In netplwiz, the checkbox option to control "must enter a password" was not displayed at all, because (as noted on that page) it will be hidden if Windows Hello is required. My system erroneously thinks that is the case. I tried the less secure "option 2" on that page using regedit... no effect at all. My system still demands a Windows Hello PIN but offers no UI to let me enter it.

@LesFerch ... yes, sorry I forgot to add that to the list of things I had already tried. No change. Neither my normal account (member of admin) nor the administrator account can log in with a password, even after net activate.
 

My Computer

System One

  • OS
    Windows 11 v10.0.22631 Build 22631
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1
    CPU
    Intel i7-1270P
    Memory
    16GB
Today, I will demonstrate the automatic Login to Windows without selecting the user account and entering the password with this coded batch script. This method works for both local user account and Microsoft account.


After you login to your account, normally try in-place upgrade.

You can also perform in-place upgrade of Windows 11. In-place upgrade is to use to replace the current operating system files on your computer. Unlike a clean installation of Windows, you can start a Windows in-place upgrade when your OS is still running. And an in-place upgrade can keep your files, settings, & apps during the upgrade process. You can perform a Windows 11 in-place upgrade is to use the Windows 11 Media Creation Tool. Make sure to select Upgrade this PC now and click Next. Follow the on-screen guide to perform a Windows 11 in-place upgrade.

 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
@FreeBooter An inplace upgrade will NOT work in safe mode so if he can not get into windows by any other method that won't work.
IMO I think the TPM's mind is scrambled. The TPM can be reset from both within Windows and in the UEFI bios. MS strongly advises it be done from within windows. I do not know if that can be done from safe mode or not either, but I doubt it.

Pay attention to the precautions listed in this tutorial and MS article and backup all personal data and all keys protected by the TPM. Even if you have to resort to clean install and have no other option except to reset the TPM from UEFI, clearing the tpm before installing would be appropriate in this case.


 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3593
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
Interesting suggestion to enable passwordless
Disable

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PasswordLess\Device]
"DevicePasswordLessBuildVersion"=dword:00000000

Do not bother with any other repairs until you have disabled Hello. It might be all you need.

I tried the less secure "option 2" on that page using regedit
I suspect that you meant Option 2 of the NetPlWiz tutorial [rather than the Hello tutorial].
I agree. I have never stored my user account password in that Registry key.


Denis
 

My Computer

System One

  • OS
    Windows 11 Home x64 Version 23H2 Build 22631.3447
have asked the OP to perform in-place upgrade after user account normal login process happens.
I understand and I should have directed that post to the OP rather than you. Sorry. I just didn't want the OP to think if none of the other suggestions worked that he could do an in-place upgrade from within safe boot.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 22631.3593
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 7080
    CPU
    i9-10900 10 core 20 threads
    Motherboard
    DELL 0J37VM
    Memory
    32 gb
    Graphics Card(s)
    none-Intel UHD Graphics 630
    Sound Card
    Integrated Realtek
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    1tb Solidigm m.2 +256gb ssd+512 gb usb m.2 sata
    PSU
    500w
    Case
    MT
    Cooling
    Dell Premium
    Keyboard
    Logitech wired
    Mouse
    Logitech wireless
    Internet Speed
    so slow I'm too embarrassed to tell
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
  • Operating System
    Windows 10 Pro 22H2 19045.3930
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex 9020
    CPU
    i7-4770
    Memory
    24 gb
    Monitor(s) Displays
    Benq 27
    Screen Resolution
    2560x1440
    Hard Drives
    256 gb Toshiba BG4 M.2 NVE SSB and 1 tb hdd
    PSU
    500w
    Case
    MT
    Cooling
    Dell factory
    Mouse
    Logitech wireless
    Keyboard
    Logitech wired
    Internet Speed
    still not telling
    Browser
    Firefox
    Antivirus
    Defender+MWB Premium
@FreeBooter - At the suggestion of @Try3 , I already tried passwordless ENABLED and DISABLED, and automated login as possible solution (it didn't work). Watching your video, I think we can assume your script just does the reg DB edits that I went through manually as @Try3 shared here. Since this does not solve my problem, @glasskuter is correct... inplace upgrade does not work in safe mode, and safe boot is my only way past the Windows Hello barrier.

@glasskuter - I also suspected that my TPM was fried. I tried resetting while in Win Safe Mode using the TPM management console; the "Reset" action was offered, but upon normal reboot I got the same old login problem. I tried to use the alternative of the Windows Security app, but it just hung with a blank screen... either a symptom of being in Safe Mode, or evidence that my TPM is corrupt. I moved on to the TPM PowerShell cmdlets [clear-tpm] and [initialize-tpm], which seemed to function normally, but a reboot in normal mode showed no change. Lastly, I resorted to EUFI/BIOS... I reset the TPM chip, rebooted, entered the Bitlocker recovery key when prompted, and... no change :( Same problem.

@Try3 - Yes, I tried both DISABLING passwordless DevicePasswordLessBuildVersion=0 and ENABLING passwordless with DevicePasswordLessBuildVersion=2. Neither one had any effect on my login problem. I enabled passwordless hoping that I could also use the automatic login to bypass Windows Hello. (and yes, as you surmised, I had to use "option 2" here). None of these configurations made any difference.

@BobOmb - Resetting my password is not the problem. I know my password, and I have already changed it a few times to see if that helps to get me past the evil Windows Hello (it doesn't).

Thank you all for the suggestions! What an impass. I am starting to think that resetting to a clean wipe Win 11 reinstall is emerging as my only path forward.

Any other ideas?
 

My Computer

System One

  • OS
    Windows 11 v10.0.22631 Build 22631
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1
    CPU
    Intel i7-1270P
    Memory
    16GB
Enable hidden administrator account from Windows 11 recovery environment and use the Admin account to reset user password, or you can use Kali Linux to reset user password to empty.

In this video, you will find detailed instructions on how to enable the hidden administrator account on Windows 11,10, 8, 7 or Vista based computers, by modifying the Windows Registry Offline in case you cannot login to Windows by using another account with admin rights.


In this guide, you’re going to learn how to reset a forgotten local user login password on any Windows computer using Kali Linux.

 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
@BobOmb - Resetting my password is not the problem.
I thought you were stuck on an ms account, the reset wouldve converted it over to a local account and in the process removed windows hello… had it been an MS account this would have likely worked.. but I see now its local..

depending on the machine set up and how much different kinds of software I had installed (and what work was involved on rebuilding my machine) I might be inclined to make a new administrator profile and slide everything from the old profile over to the new profile with something like “Fabs auto back up”

That way you don’t lose any installed software and basically get to keep nearly everything from the old profile, and your system will be running again

If you have trouble making a new admin account you can use the bootable pw reset tool in the link i sent to create one as well 😉
 

My Computer

System One

  • OS
    PE
@BobOmb - thanks for the suggestion, but I have already tried that. While in Safe Mode, I created a new account, set type to Admin and tried logging into a normal boot with that new account. Same problem... will not allow login except through Windows Hello, but there is no UI enter PIN.
 

My Computer

System One

  • OS
    Windows 11 v10.0.22631 Build 22631
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1
    CPU
    Intel i7-1270P
    Memory
    16GB
Was glancing through this. Wow. Very strange, indeed. Just a quick question: Have you tried to use the "smart card" methodology? (Lots of Google articles on this). Perhaps it will let you work around the problem? (Note: will only work with a local account - not a Microsoft account).
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell Optiplex
out of curiosity, do you have hibernate enabled? if so, try the below in safemode, in an admin cmd prompt

Batch:
powercfg /hibernate off

then reboot

It’s a longshot, but you may be having some squirrley issues with hiberfile.sys trying to load
 

My Computer

System One

  • OS
    PE
@BobOmb - no, hibernate not enabled.

Thanks again, everyone, for your great advice. I gave up and did a Windows Reset. Got all my docs, just have to reinstall apps. Bummer, but could be worse. Good thing that Safe Mode got me in!
 

My Computer

System One

  • OS
    Windows 11 v10.0.22631 Build 22631
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo X1
    CPU
    Intel i7-1270P
    Memory
    16GB
Back
Top Bottom