Windows Hello Not Working: A Practical Fix Guide
You lift the laptop lid, the camera light comes on, and for a second Windows appears to recognise you. Then the sign-in screen drops back to the PIN prompt. Fingerprint readers produce the same frustration: the sensor is present, your finger is clean, and Windows Hello still refuses to authenticate.
That failure matters because biometric sign-in is no longer an unusual convenience. The UK Information Commissioner's Office found that 58% of UK adults use fingerprint technology to access a personal device, while 46% use facial recognition and 54% consider biometrics quicker or more convenient than alternatives. The same survey found that 39% regard biometric information as more secure than a passcode. Those figures are reported in the UK passwordless authentication coverage linked to FIDO Alliance research. When Windows Hello stops working, users aren't just losing a shortcut. They're losing a sign-in method they trust and use routinely.
Table of Contents
Why Windows Hello Stops Working and What It Actually Checks - The three failure points I check first
Quick Checks Before You Touch Any Settings - Face sign-in checks - Fingerprint checks
Re-registering Your Face or Fingerprint the Right Way - When improvement isn't enough
Drivers, Biometric Service, and TPM Deep Repairs - Reinstall the device driver - Check the TPM before clearing anything
Updates, Group Policy, and Managed PC Failures - Policy settings can disable a working sensor
Fallback Options and When to Book a Repair - Know when troubleshooting has ended
Why Windows Hello Stops Working and What It Actually Checks
Windows Hello isn't one switch. Face sign-in depends on a compatible camera, usually including an infrared sensor, while fingerprint sign-in relies on a capacitive reader. Windows then passes the sensor data through the Windows Biometric Framework and Windows Biometric Service, with the Trusted Platform Module, or TPM, handling the protected cryptographic side of the sign-in process.
If one link breaks, Windows usually falls back to the PIN. That fallback doesn't necessarily mean your face or finger has suddenly changed. It can indicate a driver problem, a stopped service, a policy restriction, or a TPM state that no longer matches the Hello enrolment.

The three failure points I check first
Driver corruption often appears after Windows updates. The camera or fingerprint reader may still show in Device Manager, but the biometric provider can fail to initialise correctly.
Policy changes are common on work laptops. Group Policy, registry settings, or endpoint security rules can disable biometric providers without damaging the hardware.
TPM changes can follow a firmware update, BIOS reset, motherboard repair, or security configuration change. Hello relies on the relationship between the PIN, the biometric profile, and protected TPM keys. Break that relationship and re-enrolment may be necessary.
Practical rule: Don't begin by deleting random registry keys. Identify whether Windows can see the hardware, whether the biometric service is running, and whether the TPM reports a healthy state.
The repair sequence below follows that chain. Start with the camera or sensor, then check enrolment, services, drivers, policy, and finally the TPM. For broader Windows security troubleshooting, keep this Windows security fix guide available, but don't jump to a system rebuild while the failure is still localised to Hello.
Quick Checks Before You Touch Any Settings
Before opening Device Manager, check the physical conditions around the sensor. These simple tests solve a surprising number of cases and take only a few minutes.
Face sign-in checks
Open the webcam privacy shutter or move the privacy slider fully open. On some laptops, a physical cover blocks both the visible camera and the infrared path. If the camera has infrared illumination, look at it through a phone camera in a dim room. You may see the infrared emitters glow when Hello is active, although the exact appearance varies by hardware.
Use the Windows Camera app next. If the Camera app can't produce an image, Windows may not be seeing the webcam properly, so re-registering your face won't address the underlying fault. If the Camera app works but Hello doesn't, the problem is more likely to sit in the biometric configuration or camera selection.
Lighting matters as well. Face recognition works more reliably in an evenly lit room. Strong backlighting can leave your face in shadow, while a dirty lens, tinted glasses, a changed hairstyle, or a different camera angle can reduce recognition quality.
Fingerprint checks
Wipe the reader with a dry microfibre cloth. Oils, hand cream, damp skin, and dust can all cause repeated rejections. Clean and dry the finger you're using, then try the same finger again without pressing excessively.
At the lock screen, check that you're selecting the intended account. If more than one user is available, Windows may show an account chooser that makes the failure look like a sensor problem. Test with one account selected and confirm that the PIN option remains available.
Docking stations deserve attention. An external display or dock can alter which camera Windows exposes to applications, and Microsoft notes that external cameras can be disabled for Windows Hello face sign-in in some configurations. Before changing settings, disconnect the dock and test the laptop on its own. If you regularly create restore points, the system restore point guide explains how to prepare before deeper changes.
Re-registering Your Face or Fingerprint the Right Way
Start with the least destructive option. Sign in using your PIN, then open Settings > Accounts > Sign-in options. Under Facial Recognition (Windows Hello), choose Improve recognition and complete another scan in normal room lighting. Move your head naturally through the prompts rather than holding one rigid pose.
For fingerprints, use the option to add another finger or capture the same finger again if Windows presents that choice. A second enrolment can help when the original profile contains too narrow a range of contact angles. Don't add several poor-quality scans just to get past the setup screen. Each enrolment should be completed with a clean, dry finger and consistent pressure.

When improvement isn't enough
If recognition remains unstable, remove the affected face or fingerprint profile from Sign-in options. Restart the computer, sign in with the PIN, and enrol the biometric again. Microsoft's Windows Hello troubleshooting guidance recommends checking the camera, improving recognition, and removing and setting up facial recognition again when the profile remains unreliable.
For a more complete fingerprint reset, an administrator can stop the biometric service before clearing its database. Press Windows + R, enter , find Windows Biometric Service, set Startup type to Automatic, and choose Restart. If you need to clear a damaged local template database, the commonly used location is:
Stop the service first, copy the folder somewhere safe if possible, then remove its contents rather than deleting unrelated system files. Restart Windows, start the service again, and re-register the PIN and fingerprint from Sign-in options.
Don't perform that database step without a working account password and PIN. A damaged or incomplete reset can leave you dependent on another sign-in method, particularly on a machine whose PIN enrolment is already broken. If the PIN itself fails, reset the PIN before attempting another biometric enrolment. Microsoft community guidance also points to restarting the Windows Biometric Service and checking the biometric driver when PIN and facial recognition fail together, as described in this Microsoft Answers troubleshooting discussion.
Drivers, Biometric Service, and TPM Deep Repairs
When Windows Hello is not working after a re-enrolment, inspect the hardware path instead of repeating the same scan. Right-click the Start button and open Device Manager. Look under Biometric devices, and check Imaging devices or Cameras for face hardware.

Reinstall the device driver
If the biometric device has a warning icon, open its properties and read the device status. Record the model and driver provider first. Then choose Uninstall device. If Windows offers Delete the driver software for this device, select it only when you have a replacement path, preferably the laptop manufacturer's support page.
Restart the computer and let Windows detect the sensor again. For older Synaptics, Goodix, or ELAN readers, Windows Update may not provide the right package. Download the exact Windows driver or INF package from the laptop manufacturer's support page, matching the model and operating system, rather than selecting a similarly named reader from a third-party download site.
Open after the reboot. Windows Biometric Service should be set to Automatic and running. If it stops immediately, inspect the service dependencies and the related driver status before forcing it to start repeatedly.
Check the TPM before clearing anything
Press Windows + R, enter , and check whether the console reports that the TPM is ready for use. Errors involving ownership, provisioning, or unavailable keys need more care than a normal driver reinstall.
Clearing the TPM can remove the protected keys that Windows Hello and BitLocker depend on. Save the BitLocker recovery key before taking that step, and confirm you can sign in with another method. After a TPM clear, Windows may require BitLocker recovery during the next boot. If you don't have the recovery key, stop and recover it through the Microsoft account or the organisation's management system first.
A TPM clear is a recovery operation, not a routine Hello fix. Use it when the TPM state is clearly damaged, not because the fingerprint reader rejected a finger.
On a home computer, the TPM still matters. Windows Hello uses protected key material to complete its sign-in handshake, so a sensor that works electrically can remain unusable when the trusted platform state is wrong.
Updates, Group Policy, and Managed PC Failures
A healthy camera and a clean driver don't rule out Windows Hello failure. Updates and management policies can change what Windows is allowed to use, especially on business laptops where security settings are enforced centrally.
First, check Settings > Windows Update > Advanced options > Optional updates for biometric, camera, chipset, and firmware packages. If Hello worked before a recent quality update, record the update history before removing anything. A temporary rollback can confirm a timing relationship, but it shouldn't become a permanent security strategy. Resume normal patching once the vendor supplies a compatible fix.
Policy settings can disable a working sensor
On Windows editions that include it, run and inspect Computer Configuration > Administrative Templates > Windows Components > Biometrics. Look for policies that disable biometric use or prevent users from signing in with biometrics. On managed machines, the setting may return after a policy refresh, so the IT administrator must change the source policy rather than the local result.
The same principle applies to registry edits. Don't import a generic “Hello fix” file from the internet. A registry value that restores face sign-in could also weaken a business security baseline or conflict with endpoint management.
Cause | Where to check | Fix |
|---|---|---|
Recent Windows quality update | Windows Update history | Confirm timing, then use an approved rollback or wait for a patched build |
Biometric policy disabled | Group Policy and organisation management portal | Ask the administrator to review the policy |
Camera privacy restriction | Privacy settings, hardware shutter, camera configuration | Allow camera access and test the correct sensor |
Security-hardening compatibility issue | Windows version, security baseline, vendor advisory | Apply the vendor's supported update or workaround |
TPM or BitLocker state change | and BitLocker recovery settings | Save the recovery key before any TPM action |
Microsoft documented a specific Windows 11 24H2 issue in which enabling System Guard Secure Launch or Dynamic Root of Trust for Measurement after an update could prevent Windows Hello sign-in. The issue was later patched in build 26100.6899, as recorded in this Dell support notice covering the Windows Hello 24H2 problem. That case is important because ordinary re-enrolment won't repair a policy-driven incompatibility.
A separate camera-path problem can occur when a privacy cover or dock leaves the RGB camera disabled while the infrared camera remains available. Follow Microsoft's Windows Hello camera and biometric troubleshooting instructions, then test the intended camera configuration instead of assuming the sensor has failed.
Keep BitLocker recovery in view during every rollback or TPM operation. For organisations planning broader device changes, guidance on how to navigate the Windows 10 sunset can help separate an individual Hello fault from a wider operating-system support decision.
Fallback Options and When to Book a Repair
A biometric sign-in method should never be your only route into a computer. Confirm that your Windows Hello PIN works before you remove an enrolment, and keep the Microsoft account password available for account recovery. On a business laptop, an approved USB security key can provide another authentication route, subject to the organisation's policy.
Store the BitLocker recovery key somewhere you can reach without the affected laptop. A Microsoft account copy, an organisation's directory, or a printed record kept securely can prevent a repair from becoming a data-access emergency.

Know when troubleshooting has ended
Book a repair rather than continuing with registry edits when:
The sensor is missing: The fingerprint reader or camera doesn't appear in Device Manager, even after a full shutdown and manufacturer driver installation.
The driver loop continues: You have removed and reinstalled the correct driver, but the device repeatedly disappears or reports an error.
The TPM remains unhealthy: still reports errors after supported firmware and Windows updates.
Physical damage is likely: A drop, liquid spill, hinge repair, or screen replacement preceded the failure. Fingerprint readers can use small flex cables that are easy to damage during chassis work.
The machine is managed: A work policy or security baseline keeps reversing your changes. Your IT administrator needs to approve the repair path.
Soldered fingerprint readers and motherboard-level camera faults need an authorised service route or a workshop with board-level diagnostic capability. If the laptop is under warranty, use the OEM route before opening the chassis. For a controlled assessment of Windows, drivers, hardware, and data protection, arrange professional diagnostics rather than paying for repeated blind reinstalls.
Steel City IT provides Windows troubleshooting, hardware diagnostics, driver and sign-in repairs, and clean Windows installations for computers and laptops in Sheffield. If Windows Hello is still failing after the checks above, visit Steel City IT to arrange a practical assessment before the problem turns into a wider lockout.

