The newest version of the script checks for Windows Hello users. When the Setup Mode is required for updating certs, the TPM gets worried that something bad happened and invalidates the PIN that's securely saved.Here are my results with the "updated script", I don't get the "Windows Hello PIN" part. I guess that is because I don't have that activated on my computer.![]()
You could be unintentionally locked out from Windows if you only had the PIN option. So it's better to highlight those situations where PIN users need to exercise caution by disabling the PIN first. The same principle applies to BitLocker protection, TPM can invalidate the saved key and ask you for a recovery key on USB, or entering the recovery password. We want to avoid causing harm whenever possible.
My Computer
At a glance
Windows 7
- OS
- Windows 7









